SSCP Systems Security Certified PractitionerRisk Identification, Monitoring, and AnalysisMedium

An organization is performing a risk assessment for a new cloud service. They determine that the service has a low likelihood of a data breach, but if one were to occur, the impact would be catastrophic due to sensitive customer data being exposed. After considering various controls, they decide to implement strong encryption and multi-factor authentication, which significantly reduces the likelihood of a breach but still leaves a small chance. The remaining risk is deemed acceptable given the business benefits. What risk response strategy has the organization adopted for the remaining risk?

  1. ARisk Transfer
  2. BRisk Acceptance
  3. CRisk Mitigation
  4. DRisk Avoidance
Show answer & explanation

Correct answer: B. Risk Acceptance

The organization implemented controls (encryption, MFA) to reduce the likelihood, which is risk mitigation. However, for the 'remaining risk' that is 'deemed acceptable,' the strategy is risk acceptance. They know there's still a small chance but choose to live with it.

Why the other options are wrong

  • A. Risk transfer involves shifting the financial burden to a third party (e.g., insurance), which is not mentioned.
  • C. Risk mitigation involves implementing controls to reduce risk, which they did, but the question asks about the 'remaining risk'.
  • D. Risk avoidance means not engaging in the activity at all, which is not the case here.

Risk Acceptance

A risk response strategy where an organization decides to take no action to reduce the likelihood or impact of a risk, typically because the cost of mitigation outweighs the potential loss, or the risk is within acceptable limits.

  • Often for low-probability, low-impact risks.
  • Can be conscious (formal decision) or unconscious.
  • Always involves some level of remaining or 'residual' risk.

Memory trick: Avoid, Transfer, Mitigate, Accept - ATM-A for Risk.

More Risk Identification, Monitoring, and Analysis questions