IT Risk Management for the DISA Assessment Test
Identify, evaluate, respond, monitor. The exam tests the order and who owns each step.
IT risk is business risk that arises from the use of information and technology: a core banking outage, a ransomware attack on an ERP, a vendor that holds customer data and loses it. Module 2 of the ISA 3.0 course treats it as part of enterprise risk management, not a separate IT problem.
The auditor's job is twofold. Check that the entity has a working process to identify, assess, respond to and monitor IT risk, and use the entity's risk assessment (after challenging it) to direct your own audit effort.
You save ₹450
- Full-length timed mocks
- Module-wise practice
- Emerging-tech coverage
One payment, no subscription · Valid for 2 months
The Risk Management Process
The ISA 3.0 material sets out the cycle below. ISO 31000:2018 and NIST SP 800-30 describe the same logic in their own terms.
- 1
Identify
Build an asset inventory, a threat profile and a vulnerability assessment. Risk exists where a threat can exploit a vulnerability in an asset that matters.
- 2
Evaluate
Estimate the impact on the business if the risk materialises: financial loss, regulatory penalty, reputation, customer harm.
- 3
Determine likelihood
How probable is it, given existing controls and threat history?
- 4
Prioritise
Rank risks by impact and likelihood so that effort goes to the ones above appetite.
- 5
Respond
Choose accept, avoid, transfer or mitigate for each risk, and record the owner and the decision.
- 6
Monitor
Review risks periodically and whenever infrastructure, processes, incidents or audit findings change the picture.
The Four Risk Responses
Accept
What it means
Consciously live with a low risk and review it periodically
Example
A cooperative bank accepts the risk of a brief outage of its internal canteen app
Avoid
What it means
Remove the activity or technology that creates the risk
Example
A company drops an unsupported legacy payroll package rather than patch around it
Transfer
What it means
Shift the cost or operation to a third party, such as an insurer or service provider
Example
Cyber insurance; outsourcing data centre operations to a specialist
Mitigate
What it means
Put controls in place to reduce likelihood or impact
Example
Multi-factor authentication on the ERP; backups restored and tested
| Response | What it means | Example |
|---|---|---|
| Accept | Consciously live with a low risk and review it periodically | A cooperative bank accepts the risk of a brief outage of its internal canteen app |
| Avoid | Remove the activity or technology that creates the risk | A company drops an unsupported legacy payroll package rather than patch around it |
| Transfer | Shift the cost or operation to a third party, such as an insurer or service provider | Cyber insurance; outsourcing data centre operations to a specialist |
| Mitigate | Put controls in place to reduce likelihood or impact | Multi-factor authentication on the ERP; backups restored and tested |
Key Terms
- Inherent risk
- Risk before considering controls.
- Residual risk
- Risk that remains after controls are implemented, plus risk consciously accepted. It must sit within appetite.
- Risk appetite and tolerance
- Appetite is the amount of risk the enterprise is willing to take in pursuit of objectives; tolerance is the acceptable deviation around it. The board sets both.
- Risk register
- The record of identified risks, ratings, owners, responses and status. An auditor's first request.
- EDM03 and APO12
- In COBIT 2019, EDM03 Ensured Risk Optimisation is the board's governance objective for risk; APO12 Managed Risk is management's process to identify, assess and reduce I&T risk within tolerance.
Quick practice on audit concepts. No signup.
What RBI Now Requires of Banks
Under RBI's Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026 for commercial banks (31 July 2026), the bank's risk management policy must cover IT and cybersecurity risks, and the Risk Management Committee of the Board, with the IT Strategy Committee, must review it at least annually. The bank must also run an IT and information security risk management framework and review its security infrastructure and policies at least annually. The ISA 3.0 material predates these Directions.
How the DISA Assessment Test Tests This
Risk questions are usually about order and ownership. Watch for:
- check_circleControls before risk. The correct first step is almost always to identify assets and assess risk; picking a control first is the trap.
- check_circleTransfer means zero risk. Outsourcing or insuring moves the cost or operation, not the accountability. The entity still owns the risk.
- check_circleWho sets appetite. The board (governance), not the CIO or the IS auditor.
- check_circleResidual vs inherent. A question describing risk "after controls" wants residual risk.
- check_circleAuditor independence. The IS auditor reviews the risk assessment; owning or approving risk responses impairs independence.
FAQs
What are the four risk response options in IT risk management?expand_more
Accept, avoid, transfer and mitigate. The aim of each is to bring residual risk within the organisation's appetite and tolerance.
What is the difference between inherent risk and residual risk?expand_more
Inherent risk is the exposure before controls. Residual risk is what remains after controls are in place, including any risk management has chosen to accept.
Can ISO 31000 be used for certification?expand_more
No. ISO 31000:2018 is a guidelines standard. It gives principles, a framework and a process, and is used as a benchmark, not for certification.
Who is responsible for IT risk in an organisation?expand_more
The board sets direction and appetite and oversees risk; management owns and treats it. In Indian banks, RBI's 2026 Directions put the annual review of IT-related risk in the risk management policy with the Risk Management Committee of the Board, in consultation with the IT Strategy Committee.
Next steps
- Risk-Based Auditarrow_forward
- COBIT 2019arrow_forward
- BCP & DRarrow_forward
- Outsourcing Riskarrow_forward
Assessment Test format, timed and scored.
