Which term describes the risk level before management actions such as controls are applied?

Prepare effectively for the ISACA IT Risk Fundamentals Test. With flashcards and multiple-choice questions, each question includes hints and detailed explanations. Ace your exam confidently!

Multiple Choice

Which term describes the risk level before management actions such as controls are applied?

Explanation:
Inherent risk is the level of risk that exists before any controls are applied. It represents the baseline risk present due to the environment, processes, and inherent vulnerabilities, assuming no safeguards are in place. Think of it as the potential for adverse impact if threats exploit weaknesses without any mitigation. After controls are added, the remaining risk is called residual risk, not inherent risk. For example, a system with weak encryption has high inherent risk, but adding strong encryption reduces the residual risk while not eliminating it entirely.

Inherent risk is the level of risk that exists before any controls are applied. It represents the baseline risk present due to the environment, processes, and inherent vulnerabilities, assuming no safeguards are in place. Think of it as the potential for adverse impact if threats exploit weaknesses without any mitigation. After controls are added, the remaining risk is called residual risk, not inherent risk. For example, a system with weak encryption has high inherent risk, but adding strong encryption reduces the residual risk while not eliminating it entirely.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy