A city utility’s IRM desk learns that quarterly access reviews for SCADA admin accounts failed their last two control tests. How should that result affect the related cyber risk record?
Select an answer to reveal the explanation.
Short Explanation
Think of residual risk like a weather report after the umbrella ripped. When the control that was supposed to reduce exposure fails its tests, the leftover risk goes up—not stays flat. Link those failed compliance results so the risk record tells the truth until the fix lands.
Full Explanation
In ServiceNow IRM, residual risk is meaningful only when control effectiveness is considered. Failed or ineffective compliance controls that mitigate a risk should be linked so residual scoring and monitoring reflect reduced protection. Ignoring failed tests, deleting the risk, or auto-accepting exposure misstates the current posture for owners and regulators.