CompTIA SecurityX (CAS-005)Governance, Risk and ComplianceEasy
A CISO is reviewing the organization's overall risk posture. They have identified several high-impact, low-probability risks, such as a major natural disaster affecting the primary data center. The CISO decides to purchase specialized insurance to cover potential financial losses from such an event. Which of the following risk management strategies is the CISO employing?
- ARisk Avoidance
- BRisk Acceptance
- CRisk Transference
- DRisk Mitigation
Show answer & explanationAnswer & explanation
Correct answer: C. Risk Transference
Risk transference involves shifting the financial burden or responsibility of a risk to a third party, often through mechanisms like insurance. By purchasing specialized insurance, the CISO is transferring the financial impact of a natural disaster to the insurance provider.
Why the other options are wrong
- A. Risk avoidance means eliminating the risk by not engaging in the activity that carries the risk.
- B. Risk acceptance means acknowledging a risk and deciding to take no action to reduce its likelihood or impact.
- D. Risk mitigation involves implementing controls or measures to reduce the likelihood or impact of a risk.
Risk Transference
A risk management strategy where the potential financial impact or responsibility of a risk is shifted to a third party, typically through insurance or contractual agreements.
- Shifts financial burden.
- Commonly achieved via insurance.
- Does not eliminate the risk, but changes who bears the cost.
Memory trick: A-M-T-A: Avoid, Mitigate, Transfer, Accept.