CRISC Certified in Risk and Information Systems ControlInformation Technology and SecurityMedium

A company is implementing a new cloud-based enterprise resource planning (ERP) system. The project team identifies that a critical integration with the legacy payroll system introduces a significant data privacy risk if not handled securely. To address this, they decide to use a secure API gateway, implement end-to-end encryption for data in transit, and conduct a privacy impact assessment (PIA). This scenario BEST illustrates which aspect of risk management?

  1. ARisk monitoring and review.
  2. BRisk communication and consultation.
  3. CRisk treatment (response).
  4. DRisk identification and analysis.
Show answer & explanation

Correct answer: C. Risk treatment (response).

The scenario describes actions taken (secure API gateway, encryption, PIA) to address the identified data privacy risk. These actions fall under the 'risk treatment' or 'risk response' phase, where controls are implemented to modify the risk.

Why the other options are wrong

  • A. Monitoring and review would happen after treatment implementation, not during the decision to implement.
  • B. Communication is part of the overall process, but not the primary action described by implementing specific technical and procedural controls.
  • D. While identification and analysis occurred ('identifies a significant data privacy risk'), the core of the scenario is about the *actions taken* to deal with it.

Risk Treatment

The process of selecting and implementing measures to modify risk. It involves choosing one or more risk response strategies (e.g., mitigation, avoidance, sharing, acceptance) and putting them into action.

  • Follows risk analysis and evaluation.
  • Involves implementing controls or countermeasures.
  • Aims to reduce risk likelihood or impact.

Memory trick: Establish, Assess, Treat, Monitor, Communicate.

More Information Technology and Security questions