Which of the following is the BEST evidence of a well-defined risk event?
A.
Forensic investigations include chain-of-custody requirements
B.
Impact analyses include annual loss expectancy (ALE)
C.
Incident response plans include recovery time objectives (RTOs)
D.
Critical systems include key performance indicators (KPIs)
The Answer Is:
B
This question includes an explanation.
Explanation:
Annual Loss Expectancy (ALE) quantifies a risk event’s expected financial impact and is derived from Single Loss Expectancy (SLE) × Annualized Rate of Occurrence (ARO).
CRISC guidance states:
“A well-defined risk event includes quantified impact analysis such as annual loss expectancy to facilitate prioritization and comparison.”
Chain-of-custody and KPIs are unrelated to defining risk events.
Hence, B is correct.
CRISC Reference: Domain 2 – IT Risk Assessment, Topic: Risk Quantification and Impact Analysis.
CRISC PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 75% Discount on All Products,
Use Coupon: "ac75sure"