CRISC Certified in Risk and Information Systems ControlInformation Technology and SecurityHard

A company is integrating a third-party cloud service for its customer data. The service provider's standard contract includes a clause stating that the provider is not liable for data breaches resulting from misconfigurations by the customer. Which of the following risk management principles is BEST addressed by clearly understanding this clause?

  1. ARisk acceptance
  2. BRisk mitigation
  3. CRisk transfer
  4. DRisk avoidance
Show answer & explanation

Correct answer: C. Risk transfer

This clause explicitly shifts the liability for specific types of data breaches (customer misconfigurations) from the cloud provider to the customer. This is a classic example of risk transfer, where the financial and operational burden of the risk is contractually moved to another party.

Why the other options are wrong

  • A. Risk acceptance would be if the customer simply acknowledged the risk without contractual shifting of liability or implementing controls.
  • B. Risk mitigation would involve implementing controls (e.g., strong configuration management) to prevent misconfigurations, but the clause itself is about liability transfer.
  • D. Risk avoidance would mean not using the cloud service at all.

Risk Transfer

Risk transfer is a strategy where the financial or operational impact of a risk is shifted to another party, often through contracts or insurance.

  • Does not eliminate the risk, only reassigns its burden.
  • Commonly seen in insurance policies and service level agreements (SLAs).
  • Requires clear contractual language.

Memory trick: Contractual clauses shift the burden, not the threat.

More Information Technology and Security questions