Which term denotes the representation of risk that is tangible and assessable?

Prepare for the ISACA IT Risk Fundamentals Test. Find flashcards and multiple choice questions, complete with hints and explanations. Ace your exam with confidence!

Multiple Choice

Which term denotes the representation of risk that is tangible and assessable?

Explanation:
Representing risk as a tangible, assessable narrative is what a risk scenario provides. It describes a plausible sequence of events—an asset being exposed to a threat exploiting a vulnerability under certain conditions—that leads to a measurable impact. This concreteness lets risk managers estimate likelihood and consequence, compare scenarios, and prioritize controls. A threat event is a possible incident, but on its own doesn’t package the full risk with context and consequences. A vulnerability assessment identifies weaknesses, while a risk taxonomy classifies risk types. The scenario approach thus gives a concrete, assessable representation of risk.

Representing risk as a tangible, assessable narrative is what a risk scenario provides. It describes a plausible sequence of events—an asset being exposed to a threat exploiting a vulnerability under certain conditions—that leads to a measurable impact. This concreteness lets risk managers estimate likelihood and consequence, compare scenarios, and prioritize controls. A threat event is a possible incident, but on its own doesn’t package the full risk with context and consequences. A vulnerability assessment identifies weaknesses, while a risk taxonomy classifies risk types. The scenario approach thus gives a concrete, assessable representation of risk.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy