CRISC Certified in Risk and Information Systems Control – Question232

What should be considered while developing obscure risk scenarios? Each correct answer represents a part of the solution. Choose two.

A.
Visibility
B. Controls
C. Assessment methods
D. Recognition

Correct Answer: AD

Explanation:

Explanation:
The enterprise must consider risk that has not yet occurred and should develop scenarios around unlikely, obscure or non-historical events.
Such scenarios can be developed by considering two things:

  • Visibility
  • Recognition
  • [/*]
  • For the fulfillment of this task enterprise must:
  • [*]
  • Be in a position that it can observe anything going wrong
  • Have the capability to recognize an observed event as something wrong