Risk and Advanced Risk
CIS-RC · 75 questions
- A water utility is standing up IRM for operational technology risks and staff want to jump straight into writing individual risk records. What should come first?
- A city CIO wants a reusable definition for the risk that unpatched internet-facing civic apps can be exploited. What record should the risk team author first?
- The reusable statement for internet-facing exploitation exists. How should the risk analyst generate a register entry for the permitting system?
- Before documenting controls on the hospital EHR risk, what assessment step should the risk owner complete?
- Controls for the EHR risk are documented, including preventive MFA and compensating monitoring. What assessment comes next?
- Residual risk for missing MFA on a citizen-facing portal remains above appetite. Which response and linkage is appropriate?
- A legacy internal reporting tool has low residual risk after compensating controls, and leadership will not fund further hardening. What documented treatment fits?
- Finance proposes cyber insurance for a payments-outage risk at a municipal utility. How should that decision be reflected in IRM?
- A vulnerable public kiosk system cannot be hardened cost-effectively, and the city decides to stop offering that kiosk service. Which risk treatment is that?
- A major EHR upgrade is scheduled that changes authentication and data flows. What lifecycle action should the risk team take for related risks?
- The permitting system's entity is being decommissioned and will no longer process applications. What should happen to its scoped risks?
- Between formal assessments, a risk indicator for failed backup jobs on a utility OT network breaches its threshold. What should the risk lifecycle do?
- A newly authored risk for a payments platform is scored, owned, and ready for ongoing oversight. What state progression is appropriate?
- Business managers complete a structured questionnaire about likelihood and impact for several civic service risks. How should those results enter the lifecycle?
- For a municipal payments-outage risk, leadership wants monetary loss ranges alongside qualitative scores. What assessment input should the risk team capture?
- A city utility’s IRM desk learns that quarterly access reviews for SCADA admin accounts failed their last two control tests. How should that result affect the related cyber risk record?
- A county risk owner wants to mark a privacy breach risk Mitigated after drafting three remediation tickets. What must happen first in the risk response lifecycle?
- A hospital compliance officer asks how IRM should retain last year’s scored risk assessment after this year’s workshop revises likelihood and impact. What practice keeps history for regulators?
- After three related water-main outages, a municipal GRC team wants the pattern tracked as a managed risk in IRM—not only as closed incidents. What intake path should they use?
- A transit authority’s annual risk workshop leaves scores stale for months while ridership and vendor issues shift weekly. How does Advanced Risk continuous monitoring help in the lifecycle?
- Two county departments merge and the legacy risk owner for floodplain drainage leaves. What should the IRM administrator do on active risk records?
- A city manager wants the board pack to show cyber, facilities, and workforce risks grouped under the enterprise risk framework—not a flat dump of 200 rows. What IRM practice supports that?
- Residual risk for a clinic’s EHR downtime remains above tolerance while capital funding for redundant hosting is delayed six months. What should the risk team document now?
- A library system formally accepts residual risk on a legacy catalog server. What validation prevents that acceptance from lasting forever without revisit?
- A new IRM analyst asks for the end-to-end chain from reusable content to ongoing oversight for a civic cyber risk. Which sequence best matches the Risk and Advanced Risk lifecycle?
- In IRM architecture, how does a risk statement relate to a risk on a wastewater plant entity—parallel to control objective versus control?
- A civic board packet shows two scores for the same cyber risk. What distinction must members keep as their mental model?
- When should a municipal risk committee treat versus accept a scored risk in IRM architecture terms?
- A utility IRM lead explains the common scoring model used on qualitative risk assessments. What architecture is typically applied?
- A county finance director wants dollar-loss ranges for flood risk, while operations prefers High/Medium/Low workshops. How should methodology choice be framed?
- A transit IRM design session debates Key Risk Indicators versus underlying indicators. What architectural distinction should stick?
- Why does IRM use a risk framework instead of a random folder of risk statements?
- What makes enterprise risk registers comparable across departments and applications in IRM?
- An architect insists residual risk must drop whenever any control is linked, even if the control failed testing. What correction is required?
- How should a CIS-RC implementer describe Advanced Risk relative to core risk capabilities?
- A flood-loss estimate for a riverside plant is highly uncertain. What conceptual scoring mindset fits Advanced Risk–style quantitative thinking?
- Which statement correctly describes IRM risk treatment architecture?
- A failed control test and an open risk response both point at the same access-review gap for a clinic. What architectural construct connects them?
- An Advanced Risk designer asks how assessment configuration typically nests. Which awareness is correct?
- City council asks for risk reporting they can act on. Why is a dump of 500 raw risk rows the wrong architecture?
- A county IRM architect wants internal audit to reuse risk register data for engagement planning without making audit a second risk owner. Which architecture best preserves third-line independence?
- A utility risk team notices the register mainly updates after outages are already logged. Which design best shifts the architecture toward leading risk signals?
- A city wants the same ransomware wording assessed consistently across dozens of department applications. Which Risk architecture best enables that consistency?
- During operating-model design, a municipal CIO asks who should own residual scores versus who should configure the IRM risk application. Which separation is correct?
- A hospital IRM lead wants threat-intelligence headlines to inform risk context without converting Risk into Security Incident Response. Which approach fits?
- A transit authority’s appetite breaches currently live only in a shared spreadsheet footnote. Which architecture should replace that pattern?
- Executives want a residual heat map that reflects current assessments and indicators, not last year’s workshop slide. Which architecture supports that?
- A county register shows five near-identical ransomware statements under slightly different wording, inflating rollups. Which architecture fix is most appropriate?
- A city’s risk framework must distinguish financial, operational, compliance, and technology risks for reporting. Which design choice best supports that?
- Advanced Risk continuous monitoring is active for many civic KRIs, yet reputational and judgmental risks still need expert review. Which architecture is sound?
- A GRC administrator must configure qualitative scoring for city operational risks using likelihood and impact. Which configuration action is appropriate?
- An OT-focused risk framework is already defined for water-plant entities. What should the administrator do so statements participate in that framework?
- Security leadership wants a ransomware statement applied to every public-facing web application entity. Which configuration achieves that scoping?
- Permit-system business owners must answer structured questions during risk assessment. Which configuration step is required?
- The CIO wants automatic attention when residual scores rise above High. Which configuration implements that appetite rule?
- Risk wants an early warning when failed logins spike on the citizen portal. Which configuration is appropriate?
- The risk team wants residual context from how long critical vulnerabilities sit open—without turning the item into a Vulnerability Response implementation. Which configuration fits?
- Residual calculation should reflect controls that mitigate a payment-outage risk. What must be configured?
- When owners choose Mitigate, the team wants consistent follow-up tasks. Which configuration helps?
- Leadership prioritizes continuous monitoring on the top 20 civic risks. Which configuration action matches that intent?
- Owners must be notified when residual exceeds tolerance. Which configuration is needed?
- A utility wants annual reassessment plus extra reviews when major changes land. How should that be configured?
- Department directors should see only risks tied to their entities. Which configuration approach is appropriate?
- A new municipal IRM rollout needs a starting set of IT risk statements quickly, then local tailoring. Which configuration path is sound?
- Finance wants estimated primary loss captured on a payment-outage risk alongside qualitative ratings. Which configuration awareness is correct?
- A county hospital's risk assessment for the EHR marks the residual score above appetite and flags the risk as needing treatment. How should the IRM admin wire the next step so remediation work starts without a spreadsheet handoff?
- A municipal utility wants any risk acceptance above a published residual threshold to require senior approval before the register shows Accepted. What should the implementer configure?
- A regional clinic maps ransomware exposure on its EHR entity and a related identity-provider entity that issues clinician SSO. What IRM configuration best captures that the EHR risk depends on the identity provider's posture?
- A transit authority GRC lead needs executives to see the highest residual risks grouped by entity class (Application, Facility, Vendor) on one board. What should be configured?
- A water utility is standing up Advanced Risk assessments for operational-technology assets and needs likelihood and impact factors weighted for OT criticality. Where should those factors and weights live?
- A county GRC admin notices retired clinic applications still spawning new generated risks every week. What configuration change stops that noise without deleting historical risk history?
- A municipal generator-test program can only prove monthly load-bank results with paper logs that no API can read. How should indicator collection be configured for that KRI?
- Three civic departments each invent their own 1–7 impact scales for Advanced Risk, making board heat maps incomparable. What is the sounder approach?
- A hospital board wants residual and inherent risk trends in the same executive Performance Analytics-style views used for other operational KPIs. What is the primary purpose of that integration?
- A transit GRC lead wants risk owners to update scores and responses while auditors and many managers may only view the register. What should be tuned?