CRISC Exam Question: Risks Associated with Information Dissemination

Mitigating Risks of Ineffective Information Distribution

Prev Question Next Question

Question

Which of the following risks is associated with not receiving the right information to the right people at the right time to allow the right action to be taken?

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D.

A.

Relevance risk is the risk associated with not receiving the right information to the right people (or process or systems) at the right time to allow the right action to be taken.

Incorrect Answers: B: The risk that data cannot be relied on because they are unauthorized, incomplete or inaccurate is termed as integrity risk.

C: The risk of loss of service or that data is not available when needed is referred as availability risk.

D: The risk that confidential or private information may be disclosed or made available to those without appropriate authority is termed as access or security risk.

An aspect of this risk is non-compliance with local, national and international laws related to privacy and protection of personal information.

The risk associated with not receiving the right information to the right people at the right time to allow the right action to be taken is a form of Availability Risk. Availability risk refers to the risk that information or resources will not be available to authorized users when they need them.

In this case, the risk is related to the availability of information, specifically the availability of relevant information at the right time. If information is not available when needed, it can lead to delays or incorrect decisions, which can have a negative impact on an organization's operations, reputation, and financial performance.

For example, if an organization's incident response team does not receive timely and accurate information about a security incident, they may not be able to respond quickly enough to prevent further damage. This could result in data loss, system downtime, or other negative consequences.

In contrast, Relevance risk refers to the risk that the information presented is not relevant to the situation or decision-making process, Integrity risk refers to the risk that data or systems have been compromised or tampered with, and Access risk refers to the risk that unauthorized users can access or modify information or systems.

Therefore, the correct answer to the question is C. Availability risk.