ISACA IT Risk Fundamentals — Question 2
Which of the following provides the MOST important input for analyzing I&T-related risk?
Answer options
- A. Information about market trends and technology evolution
- B. Information about past incidents, frequency, and loss to the organization
- C. Information about threats and vulnerabilities
Correct answer: B
Explanation
The correct answer, B, emphasizes the significance of understanding past incidents as they provide concrete evidence of risks faced by the organization. This historical data is essential for predicting future risks. Options A and C, while relevant, do not offer the same level of direct insight into the organization's specific risk profile.