CRISC Certified in Risk and Information Systems ControlInformation Technology and SecurityEasy
A financial institution is implementing a new customer relationship management (CRM) system. During the risk assessment, it is identified that a critical component of the system relies on a third-party vendor with a history of minor security incidents. The institution decides to implement additional internal monitoring and a more stringent service level agreement (SLA) with the vendor. Which of the following risk responses does this scenario primarily demonstrate?
- ARisk Acceptance
- BRisk Transfer
- CRisk Avoidance
- DRisk Mitigation
Show answer & explanationAnswer & explanation
Correct answer: D. Risk Mitigation
Implementing additional internal monitoring and a more stringent SLA are actions taken to reduce the likelihood or impact of the identified risk, which is the definition of risk mitigation.
Why the other options are wrong
- A. Risk acceptance means acknowledging the risk and taking no action to reduce it.
- B. Risk transfer involves shifting the risk to another party, often through insurance or contracts, without necessarily reducing the risk itself.
- C. Risk avoidance involves eliminating the activity causing the risk entirely.
Risk Mitigation
Risk mitigation involves implementing controls or actions to reduce the likelihood or impact of a risk event.
- Aims to decrease risk exposure.
- Can involve technical, administrative, or physical controls.
- Often a cost-benefit analysis is performed.
Memory trick: ARM-T: Avoid, Reduce, Mitigate, Transfer