CRM EXAM PART 2.B.2 - RISK ASSESSMENTS AND
MITIGATION WITH ALL CORRECT & 100% VERIFIED
ANSWERS|ALREADY GRADED A+
Risk Assessment ✔Correct Answer-Identification, evaluation, and estimation of the levels of risks
to which an organization may be exposed in a situation, their comparison against benchmarks or
standards, and whether it would be in the organization's best interest to take certain measures to
reduce these risks to a level that is considered to be acceptable.
A __________ risk assessment is usually based on a physical survey of locations where vital records
are stored.
a) compliance
b) financial
c) quantitative
d) confidential
e) qualitative ✔Correct Answer-e) qualitative
Risk Identification ✔Correct Answer-Process of determining risks that could potentially prevent the
program, enterprise, or investment from achieving its objectives. It includes documenting and
communicating the concern, its sources, area of impact, and causes and consequences of risk.
Risk Analysis ✔Correct Answer-Process of identifying and evaluating specific risks; causes,
consequences, likelihood and risk level. The outcome of risk analysis provides the basis for protection
planning and other records management decisions.
Risk Evaluation ✔Correct Answer-Process used to compare the estimated risk against the given risk
criteria so as to determine the significance of the risk. In other words, level of risk compared to
tolerance.
Risk Tolerance ✔Correct Answer-- level of risk or degree of uncertainty that is acceptable to
organizations and is a key element of the organizational risk frame
- amount of corporate data and systems that can be risked to an acceptable level
- having this defined means the security program knows the degree that management requires the
organization to be protected against confidentiality, integrity, or availability compromise
What determines an organization's risk tolerance? ✔Correct Answer-- compliance and privacy
obligations
- perceived security threats
- data and asset value
- industry and competitive pressure
- management preferences
High Risk Tolerance ✔Correct Answer-- organization does not operate within the following areas:
Finance, Health care, Telecom, Government, Research, Education
- no compliance requirements
- no sensitive data
- customers do not expect you to implement and maintain strong security controls
- innovation and revenue generation comes before security, so more risk is accepted
, - does not have remote locations
Medium Risk Tolerance ✔Correct Answer-- organization operates within the following areas:
Government, Research, Education
- some compliance requirements (e.g. HIPAA, PIPEDA)
- some sensitive data, are required to retain records
- customers will eventually need strong security controls for their activities
- due to the sensitive data, information security is more visible to senior management
- has some remote locations
Low Risk Tolerance ✔Correct Answer-- organization operates within the following areas: Finance,
Health care, Telecom
- multiple compliance requirements and house sensitive - customers require and expect your
organization to have and maintain strong security controls.
- information security is highly visible to senior
- has multiple remote locations
Risk Capacity ✔Correct Answer-How much an organization is willing to lose without jeopardizing
its goals.
Administrative Risks ✔Correct Answer-- lack of documentation to mitigate threats and
vulnerabilities
- lack of security awareness and training
- lack of roles delegation
- not having or failing to periodically reviewing/update policies and procedures
- failing to review information system activity
Recordkeeping System Risks ✔Correct Answer-- weak records protection as part of emergency
management
- indiscriminate application of Information technology end tools without effective recordkeeping
- multiplication of digital records and information, increasing the danger of security breaches, losses,
confusion, and mismanagement
- inadequate PII and security protections
- lack of awareness of the importance of records as evidence
Records Risks ✔Correct Answer-- malicious destruction
- accidental destruction
- careless handling
- misfiled records
- stolen recorded information
- computer hardware and software failures
- tampering
- improper disclosure of recorded information
Records Risk Control ✔Correct Answer-Techniques that reduce the frequency or severity of losses
such as protective or preventative measures:
- one storage location is easier to secure than many
- access to vital records storage areas should be limited to a single supervised entrance and restricted
to authorized individuals
- employees should be instructed to challenge and report suspect persons who enter vital records
repositories
MITIGATION WITH ALL CORRECT & 100% VERIFIED
ANSWERS|ALREADY GRADED A+
Risk Assessment ✔Correct Answer-Identification, evaluation, and estimation of the levels of risks
to which an organization may be exposed in a situation, their comparison against benchmarks or
standards, and whether it would be in the organization's best interest to take certain measures to
reduce these risks to a level that is considered to be acceptable.
A __________ risk assessment is usually based on a physical survey of locations where vital records
are stored.
a) compliance
b) financial
c) quantitative
d) confidential
e) qualitative ✔Correct Answer-e) qualitative
Risk Identification ✔Correct Answer-Process of determining risks that could potentially prevent the
program, enterprise, or investment from achieving its objectives. It includes documenting and
communicating the concern, its sources, area of impact, and causes and consequences of risk.
Risk Analysis ✔Correct Answer-Process of identifying and evaluating specific risks; causes,
consequences, likelihood and risk level. The outcome of risk analysis provides the basis for protection
planning and other records management decisions.
Risk Evaluation ✔Correct Answer-Process used to compare the estimated risk against the given risk
criteria so as to determine the significance of the risk. In other words, level of risk compared to
tolerance.
Risk Tolerance ✔Correct Answer-- level of risk or degree of uncertainty that is acceptable to
organizations and is a key element of the organizational risk frame
- amount of corporate data and systems that can be risked to an acceptable level
- having this defined means the security program knows the degree that management requires the
organization to be protected against confidentiality, integrity, or availability compromise
What determines an organization's risk tolerance? ✔Correct Answer-- compliance and privacy
obligations
- perceived security threats
- data and asset value
- industry and competitive pressure
- management preferences
High Risk Tolerance ✔Correct Answer-- organization does not operate within the following areas:
Finance, Health care, Telecom, Government, Research, Education
- no compliance requirements
- no sensitive data
- customers do not expect you to implement and maintain strong security controls
- innovation and revenue generation comes before security, so more risk is accepted
, - does not have remote locations
Medium Risk Tolerance ✔Correct Answer-- organization operates within the following areas:
Government, Research, Education
- some compliance requirements (e.g. HIPAA, PIPEDA)
- some sensitive data, are required to retain records
- customers will eventually need strong security controls for their activities
- due to the sensitive data, information security is more visible to senior management
- has some remote locations
Low Risk Tolerance ✔Correct Answer-- organization operates within the following areas: Finance,
Health care, Telecom
- multiple compliance requirements and house sensitive - customers require and expect your
organization to have and maintain strong security controls.
- information security is highly visible to senior
- has multiple remote locations
Risk Capacity ✔Correct Answer-How much an organization is willing to lose without jeopardizing
its goals.
Administrative Risks ✔Correct Answer-- lack of documentation to mitigate threats and
vulnerabilities
- lack of security awareness and training
- lack of roles delegation
- not having or failing to periodically reviewing/update policies and procedures
- failing to review information system activity
Recordkeeping System Risks ✔Correct Answer-- weak records protection as part of emergency
management
- indiscriminate application of Information technology end tools without effective recordkeeping
- multiplication of digital records and information, increasing the danger of security breaches, losses,
confusion, and mismanagement
- inadequate PII and security protections
- lack of awareness of the importance of records as evidence
Records Risks ✔Correct Answer-- malicious destruction
- accidental destruction
- careless handling
- misfiled records
- stolen recorded information
- computer hardware and software failures
- tampering
- improper disclosure of recorded information
Records Risk Control ✔Correct Answer-Techniques that reduce the frequency or severity of losses
such as protective or preventative measures:
- one storage location is easier to secure than many
- access to vital records storage areas should be limited to a single supervised entrance and restricted
to authorized individuals
- employees should be instructed to challenge and report suspect persons who enter vital records
repositories