What consists of the identification of risks or threats, the implementation of…
2025
What consists of the identification of risks or threats, the implementation of security measures, and the monitoring of those measures for effectiveness?
- A.
Risk assessment
- B.
Security
- C.
Risk Management
- D.
None of the above
Attempted by 23 students.
Show answer & explanation
Correct answer: C
Risk Management, in an IT/cyber-security context, is the continuous governance process an organization runs to handle threats to its systems and information.
It has three linked stages: identifying and analysing risks or threats, selecting and implementing security controls to address them, and then monitoring those controls on an ongoing basis to confirm they remain effective, feeding results back into the cycle.
The stem names exactly these three linked activities together — identification of risks or threats, implementation of security measures, and monitoring of those measures for effectiveness — which describes the full lifecycle rather than any single stage of it.
Risk assessment is only the identifying-and-analysing stage of the cycle — it stops before any control is implemented or monitored.
Security names the protective goal or state an organization is aiming for, not the staged activity of identifying, implementing, and monitoring controls.
None of the above is not applicable, since a standard term for exactly this process is present among the given options.
Because the stem spans all three linked stages together, Risk Management is the term that matches.