Study. uk . com
  1. Home
  2. All questions
  3. Question 258

CISM study material · question 258 of 1000

IR 8286 prefers current risk to inherent risk in its register template. What reasoning does it give?

  1. Some mitigating elements are almost always already present, so a true absence of controls is rarely the real baseline
  2. Current risk is required by the international standards the organisation reports against, and inherent risk is not recognised there
  3. Inherent risk is a term reserved for financial and credit risk, and cannot properly be applied to a cybersecurity exposure at all
  4. Inherent risk cannot be quantified
Show the answer

Answer: A. Some mitigating elements are almost always already present, so a true absence of controls is rarely the real baseline

IR 8286 notes that references to inherent risk describe conditions in the absence of risk management actions, but that there are often at least some elements helping mitigate risks, so it refers to current risk as the baseline posture.

Source: NIST IR 8286 (NIST) — Sec. 3 Risk Register Elements

Challenge yourself on this topic → Study as cards