A company is implementing a new cloud-based customer relationship management (CRM) system. The IT risk manager needs to assess the risk of data exfiltration by a malicious insider at the cloud provider. Which risk assessment approach is most appropriate for this scenario?
Scenario analysis directly models the malicious-insider threat at the cloud provider, assessing how plausible exfiltration is and the resulting business impact. It satisfies the stem's requirement to evaluate a specific, low-frequency, high-consequence risk that quantitative historical data cannot reliably support, unlike generic control checklists or compliance audits.
Why this answer
Scenario analysis is most appropriate because the risk of data exfiltration by a malicious insider at the cloud provider is a complex, low-frequency, high-impact threat that is difficult to quantify with historical data. This approach allows the risk manager to systematically evaluate specific attack paths (e.g., an insider with database access copying customer records) by focusing on likelihood and impact, which aligns with the qualitative nature of insider threat assessment in a cloud environment.
Exam trap
The trap here is that candidates often choose quantitative risk assessment (A) because it seems more rigorous, but they fail to recognize that insider threats at a cloud provider lack the historical data needed for ALE/SLE calculations, making scenario analysis the practical and most appropriate approach per CRISC best practices.
How to eliminate wrong answers
Option A is wrong because quantitative risk assessment using ALE and SLE requires reliable historical data on frequency and loss magnitude, which is typically unavailable for malicious insider threats at a cloud provider due to the rarity and variability of such events. Option B is wrong because the COSO ERM framework is an enterprise-level governance and internal control framework, not a specific risk assessment methodology for analyzing a discrete technical threat like data exfiltration by a cloud provider insider. Option D is wrong because control self-assessment (CSA) against ISO 27001 evaluates the effectiveness of existing controls against a standard, but it does not directly assess the likelihood and impact of a specific threat scenario like malicious insider data exfiltration.