Issues, events, incidents, and breaches
This section is not specifically included in the CRISC exam syllabus, but it is important for an IT risk manager to understand certain terminologies. I have seen many experienced risk professionals use these terms interchangeably, but that’s not correct. The following list details the definitions of each term:
- Issues – This is an instance of IT risk that has not materialized at all but needs to be considered and kept on the radar. This is a combination of control, value, and threat conditions that impose a noteworthy level of risk. One example of an issue could be outdated operating systems that are still being used by employees. Though nothing is wrong with using an outdated operating system and delaying the update by a few weeks while it’s being tested, it should be noted as an issue, and the operating system should be updated at the earliest opportunity.
- Events – This is any occurrence that takes place...