🔥 3-day streak
ISACA CRISC — Certified in Risk and Information Systems Control69 / 150
Question 69 of 150

A risk analyst at a mid-sized bank is estimating the likelihood of a ransomware event for the risk register. The organization has been operating for only three years and has experienced no ransomware incidents, so internal historical loss data is sparse. Management wants a defensible frequency estimate. Which approach BEST improves the credibility of the likelihood estimate?

Reviewed for accuracy · Report an issueNext question