A new IRM analyst asks for the end-to-end chain from reusable content to ongoing oversight for a civic cyber risk. Which sequence best matches the Risk and Advanced Risk lifecycle?
Select an answer to reveal the explanation.
Short Explanation
Picture a conveyor belt: framework shelves the topics, statements define the threat, risks put it on an entity, then you assess, respond, and keep watching. Starting with monitor-only or skipping straight to audit citations skips the risk lifecycle.
Full Explanation
The Risk and Advanced Risk lifecycle typically progresses from framework organization to risk statements, generation of scoped risk instances, assessment and scoring, response treatments, and ongoing monitoring with indicators. Reversing that order or substituting an audit-and-citation-only path does not establish the full risk management chain.