Certified Information Security Manager (CISM)Information Security Risk ManagementEasy

An organization has identified a critical vulnerability in a legacy system that cannot be patched without significant operational disruption. The information security manager proposes implementing a firewall rule to restrict access to the system only from specific, hardened jump servers. Which risk treatment strategy is being applied?

  1. ARisk transfer
  2. BRisk acceptance
  3. CRisk avoidance
  4. DRisk mitigation
Show answer & explanation

Correct answer: D. Risk mitigation

Implementing controls like a firewall rule to reduce the likelihood or impact of a risk, without eliminating the risk entirely, is known as risk mitigation. The vulnerability still exists, but its exposure is reduced.

Why the other options are wrong

  • A. Risk transfer would involve shifting the risk to another party, such as through insurance.
  • B. Risk acceptance would mean acknowledging the risk and taking no action to reduce it.
  • C. Risk avoidance would mean shutting down or not using the legacy system entirely.

Risk Mitigation

The process of implementing controls or countermeasures to reduce the likelihood or impact of identified risks to an acceptable level.

  • Aims to reduce risk likelihood or impact.
  • Involves implementing security controls.
  • Does not eliminate the risk entirely.

Memory trick: Avoid, Transfer, Mitigate, or Accept the risk.

More Information Security Risk Management questions