Summary
At the beginning of this chapter, we learned about the differences between risk assessment and BIA. We learned that the primary goal of BIA is to determine how quickly critical business operations should be recovered in case of an incident to avoid further damage; however, the primary goal of a risk assessment is to identify potential threats to an organization and surface the risks and implement adequate measures.
We then learned about related concepts, such as BC, DR, RPO, RTO, and MTD, which speak to how an organization should determine the recovery objectives of critical systems. In the next section, we switched gears to learn more about inherent risk, residual risk, and current risk, which helps risk managers quantify the remaining risks after all the controls are implemented.
In the next chapter, we will learn about risk response and control ownership, which also marks the beginning of Domain 3 – Risk Response and Reporting per the official CRISC exam outline...