📢 Too many exams? Don’t know which one suits you best? Book Your Free Expert 👉 call Now!

  • google app store apple app store
  • âś–

      Question

      What is 'Risk Assessment' in the context of IT security

      for banks?
      A The systematic process of identifying assets, identifying threats and vulnerabilities, evaluating the likelihood and impact of risks, and prioritizing mitigation actions Correct Answer Incorrect Answer
      B The process of testing software applications for bugs and errors to ensure that the application will run smoothly at the user end. Correct Answer Incorrect Answer
      C The annual financial audit of IT department expenditures where all financial aspects are looked into. Correct Answer Incorrect Answer
      D The process of purchasing cybersecurity insurance for IT assets so that the IT assets are protected from any kind of attack. Correct Answer Incorrect Answer
      E The evaluation of employee performance on security awareness that assesses the level of risk for an organization from cyberattacks. Correct Answer Incorrect Answer

      Solution

      Risk Assessment process:  1) Asset Identification (critical systems, data, processes). 2) Threat Identification (hackers, insiders, natural disasters).  3) Vulnerability Identification (weak passwords, unpatched systems).  4) Risk Analysis — Qualitative (High/Medium/Low matrix) or Quantitative (ALE = ARO × SLE).  5) Risk Treatment: Accept, Avoid, Transfer (insurance), Mitigate.  RBI's IT Risk and Cyber Security Framework mandates formal risk assessments for all banks. ISO 27001 and NIST frameworks guide structured risk management.

      Practice Next

      Relevant for Exams:

      ask-question