The reusable statement for internet-facing exploitation exists. How should the risk analyst generate a register entry for the permitting system?
Select an answer to reveal the explanation.
Short Explanation
The statement is the recipe; scoping it to the permitting system is pouring the cake. That scoped apply is what puts a real risk on the register.
Full Explanation
Generating risk instances from scoped statements attaches the reusable statement to a specific entity such as the permitting system. Unscoped assumptions, knowledge articles, or ITSM changes do not create the IRM risk register entry the lifecycle requires.