CRISC Certified in Risk and Information Systems ControlInformation Technology and SecurityMedium

An organization is conducting a security audit of its cloud infrastructure. The auditor discovers that several critical virtual machines (VMs) are running with default administrative credentials and unpatched operating systems. Which of the following risk management strategies is MOST appropriate to address these findings immediately?

  1. ARisk Acceptance
  2. BRisk Transfer
  3. CRisk Avoidance
  4. DRisk Mitigation
Show answer & explanation

Correct answer: D. Risk Mitigation

Risk mitigation involves implementing controls or countermeasures to reduce the likelihood or impact of a risk. Patching systems and changing default credentials are direct actions to reduce the identified vulnerabilities and thus mitigate the associated risks.

Why the other options are wrong

  • A. Risk acceptance means doing nothing, which is inappropriate for critical vulnerabilities.
  • B. Risk transfer would involve shifting the risk to a third party (e.g., insurance), which doesn't address the underlying technical vulnerabilities directly.
  • C. Risk avoidance would mean not using VMs or cloud, which is not an immediate solution to existing vulnerabilities.

Risk Mitigation

A risk management strategy that involves taking actions to reduce the likelihood of a risk event occurring or to lessen the impact if it does occur.

  • Involves implementing controls and countermeasures.
  • Common strategy for high-impact, high-likelihood risks.
  • Examples: patching, strong authentication, encryption.

Memory trick: Avoid, Accept, Mitigate, Transfer.

More Information Technology and Security questions