ある組織は、データセンターのセキュリティカメラの映像を、ポリシーで90日間の保存が義務付けられているにもかかわらず、30日間保存しています。経営者は、状況を改善する価値があるかどうか疑問視しています。リスク管理者にとって最善の対応は次のどれですか。
正解:C
A risk is the possibility of an event that may have a negative impact on the achievement of an organization's objectives. A risk can be measured by the probability and impact of the event, which indicate the likelihood and consequence of the event. A risk manager is a person who is responsible for performing risk management activities, such as identifying, analyzing, evaluating, treating, monitoring, and communicating risks. When an organization retains footage from its data center security camera for 30 days when the policy requires 90-day retention, the risk manager's best response to the business owner who challenges whether the situation is worth remediating is to evaluate the risk as a measure of probable loss, which means to estimate thepotential harm or damage that may result from the non-compliance with the policy. By evaluating the risk as a measure of probable loss, the risk manager can provide the business owner with the rationale and justification for the risk remediation, and help the business owner to understand the cost-benefit analysis of the risk response. References = CRISC Review Manual, 7th Edition, page 63.