CRISC Certified in Risk and Information Systems ControlInformation Technology and SecurityEasy

A financial institution is implementing a new customer relationship management (CRM) system. During the risk assessment, it is identified that a critical component of the system relies on a third-party vendor with a history of minor security incidents. The institution decides to implement additional internal monitoring and a more stringent service level agreement (SLA) with the vendor. Which of the following risk responses does this scenario primarily demonstrate?

  1. ARisk Acceptance
  2. BRisk Transfer
  3. CRisk Avoidance
  4. DRisk Mitigation
Show answer & explanation

Correct answer: D. Risk Mitigation

Implementing additional internal monitoring and a more stringent SLA are actions taken to reduce the likelihood or impact of the identified risk, which is the definition of risk mitigation.

Why the other options are wrong

  • A. Risk acceptance means acknowledging the risk and taking no action to reduce it.
  • B. Risk transfer involves shifting the risk to another party, often through insurance or contracts, without necessarily reducing the risk itself.
  • C. Risk avoidance involves eliminating the activity causing the risk entirely.

Risk Mitigation

Risk mitigation involves implementing controls or actions to reduce the likelihood or impact of a risk event.

  • Aims to decrease risk exposure.
  • Can involve technical, administrative, or physical controls.
  • Often a cost-benefit analysis is performed.

Memory trick: ARM-T: Avoid, Reduce, Mitigate, Transfer

More Information Technology and Security questions