Certified in Risk and Information Systems Control (CRISC) — Question 678
Which of the following is the BEST way to identify changes to the risk landscape?
Answer options
- A. Access reviews
- B. Root cause analysis
- C. Internal audit reports
- D. Threat modeling
Correct answer: D
Explanation
Threat modeling is the best approach because it systematically identifies and evaluates potential threats to an organization's assets, thereby enabling proactive risk management. Access reviews, root cause analysis, and internal audit reports serve different purposes and may not directly address the ongoing changes in the risk landscape.