CRISC Certified in Risk and Information Systems ControlInformation Technology and SecurityEasy
A financial institution is implementing a new online banking platform. During the project's risk assessment, it's identified that a potential denial-of-service (DoS) attack could disrupt services, leading to significant financial losses and reputational damage. The institution decides to purchase cyber insurance that specifically covers losses incurred from such attacks. Which risk response strategy is being employed?
- ARisk Mitigation
- BRisk Sharing
- CRisk Avoidance
- DRisk Acceptance
Show answer & explanationAnswer & explanation
Correct answer: B. Risk Sharing
Purchasing cyber insurance transfers a portion of the financial impact of a risk to a third party (the insurer), which is a form of risk sharing.
Why the other options are wrong
- A. Risk mitigation involves taking steps to reduce the likelihood or impact of a risk, such as implementing DDoS protection.
- C. Risk avoidance involves eliminating the activity or condition that gives rise to the risk.
- D. Risk acceptance involves acknowledging the risk and taking no action to reduce its likelihood or impact.
Risk Sharing
A risk response strategy where the organization distributes the burden of a risk with another party, often through contracts, insurance, or partnerships.
- Involves collaboration with a third party.
- Distributes potential losses or impacts.
- Commonly achieved through insurance policies.
Memory trick: Always Share, Avoid, Mitigate, or Accept risks.