A regional clinic maps ransomware exposure on its EHR entity and a related identity-provider entity that issues clinician SSO. What IRM configuration best captures that the EHR risk depends on the identity provider's posture?
Select an answer to reveal the explanation.
Short Explanation
If the clinic's login keys fall over, the EHR risk gets worse — those two risks are hitchhikers. Relating them as dependent related risks keeps that story visible without smushing two entities into one fake CI. Unrelated duplicates hide the chain.
Full Explanation
IRM supports relating risks across entities so dependency and cascading exposure stay visible. An EHR risk that depends on identity-provider controls should use a related-risk relationship rather than merging entities or creating orphan duplicates. That preserves entity scope while documenting cross-entity impact.