CompTIA Security+ (SY0-701)Security Program Management and OversightHard
An organization determines that fully mitigating a particular risk would cost more than the potential loss itself. Instead of implementing additional controls, the organization purchases a cyber insurance policy to cover potential financial losses from that risk. Which risk treatment strategy has been applied?
- ARisk mitigation
- BRisk avoidance
- CRisk acceptance
- DRisk transference
Show answer & explanationAnswer & explanation
Correct answer: D. Risk transference
Risk transference shifts the financial impact of a risk to a third party, such as through purchasing insurance, rather than reducing the likelihood or impact directly through controls.
Why the other options are wrong
- A. Risk mitigation involves implementing controls to reduce risk, which the organization decided against due to cost.
- B. Risk avoidance means eliminating the activity that causes the risk entirely, which was not done here.
- C. Risk acceptance means taking no action and absorbing potential losses, whereas insurance shifts that burden elsewhere.
Risk Transference
A risk treatment strategy that shifts the financial or operational impact of a risk to a third party, commonly through insurance or outsourcing.
- Common example: purchasing cyber insurance
- Does not reduce likelihood or impact directly
- Differs from acceptance, which retains the risk internally
Memory trick: Transfer the Bill to an Insurance Firm