Domain 2: Governance and Management of IT9 min · 3 questions

IT Risk Management: Identification, Assessment and Response

Identify, assess, respond, monitor. The exam tests the order, the vocabulary of the four responses, and who is actually allowed to choose.

What this makes you able to do

Evaluate an organisation's IT risk management process against the identify, assess, respond and monitor lifecycle.

By the end you can

  • Order the risk management lifecycle and state what each stage produces.
  • Name the four risk responses and match each to a scenario.
  • Distinguish the roles of the risk owner, the control owner and the auditor.

Transcript

I-T risk management. This lesson is about the risk lifecycle, the four ways to respond to a risk, and who is actually allowed to choose. The exam tests the order and the vocabulary directly.

Here is the situation. A team spots that a legacy system has no logging. Within a day, someone has bought a logging tool, someone else has written a policy, and a third person has quietly decided the whole thing is probably fine. Three responses, and not one person has worked out how likely a problem is, or how bad it would be. They skipped assessment.

And that is the cardinal error. Just as risk-based audit planning demands you assess before you allocate effort, risk management demands you assess before you respond. A control chosen before assessment is guesswork. It may over-spend on a trivial exposure or under-treat a severe one. So when a question asks what to do next after identifying a risk, the answer is almost always, assess it.

The lifecycle runs in order: identify the risks, assess each one’s likelihood and impact, respond with something proportionate to the assessed size, then monitor over time and reassess as things change. The step candidates skip is the second one, assessment, and it is the one the exam guards most.

Once a risk is assessed, there are exactly four things you can do with it. First, mitigate, or reduce: apply controls that lower the likelihood or the impact. Most controls are mitigation.

Second, transfer, or share: shift the financial consequence to a third party, typically through insurance or a contract. The event can still happen; what changes is who bears the loss.

Third, accept: bear the risk with no further action, which is legitimate when it sits within appetite and treatment would cost more than it saves. And fourth, avoid: stop the activity that creates the risk, for example by not collecting the data at all.

A favourite trap: calling insurance mitigation. It is transfer. Mitigation changes the risk itself, its likelihood or impact. Transfer only moves the financial consequence, and it moves the money, not the underlying obligation or the reputational harm.

Now, who decides the response. It is the risk owner, the person accountable for the process or asset the risk affects. They choose to mitigate, transfer, accept or avoid, within the appetite the board has set. The auditor identifies and evaluates the risk and reports on it, but must not choose the response, because making that management decision destroys independence, exactly as in Domain 1.

And there is one risk that is yours. You cannot change inherent risk or control risk, those belong to management. The only risk the auditor moves is detection risk. So a question asking what you should do about high control risk is asking about the audit response, which is more testing, not about fixing the control.

Which brings us to the trap. The instinct, the moment a risk appears, is to reach for a control. It feels responsible, and it is premature. Assess first, then let the risk owner choose a response proportionate to what the assessment found.

So carry this away. After identifying a risk, the next step is almost always to assess it. And the response decision belongs to the business risk owner, not to the auditor, and not to the security team.

Knowledge check
0 / 3
  1. 1.An organisation identifies a new IT risk. What should management do NEXT?

  2. 2.An organisation buys cyber-insurance to cover the financial loss from a potential data breach. Which risk response is this?

  3. 3.Who is PRIMARILY responsible for deciding how to respond to an identified IT risk?

Independent training produced by Marco Cavani. Not affiliated with, endorsed by, or sponsored by ISACA. CISA is a registered trademark of ISACA. Practice questions are written for this course and are not reproduced from ISACA materials.

Stay ahead of cyber threats

Get the latest cybersecurity reports, threat intelligence, and IT governance insights delivered straight to your inbox. No spam. Unsubscribe any time.

No spam. Unsubscribe at any time.