SSCP Systems Security Certified PractitionerRisk Identification, Monitoring, and AnalysisHard

During a security audit, an organization discovers that several critical servers are running outdated operating systems with known, unpatched vulnerabilities. Management is aware of the risk but has decided to accept it due to the high cost and potential downtime associated with upgrading the legacy systems. This decision represents which type of risk response strategy?

  1. ARisk Acceptance
  2. BRisk Transfer
  3. CRisk Avoidance
  4. DRisk Mitigation
Show answer & explanation

Correct answer: A. Risk Acceptance

Risk acceptance is the decision to take no action to reduce the likelihood or impact of a risk, typically because the cost of mitigation outweighs the potential loss or because the risk is deemed low enough to tolerate. In this case, management explicitly acknowledged and decided to live with the risk.

Why the other options are wrong

  • B. Risk transfer means shifting the financial burden of a risk to a third party, like insurance.
  • C. Risk avoidance means eliminating the risk by stopping the activity that causes it.
  • D. Risk mitigation means taking steps to reduce the likelihood or impact of the risk.

Risk Acceptance

A risk management strategy where an organization consciously decides to bear the potential consequences of a risk without implementing specific controls to reduce it.

  • Typically occurs when the cost of mitigation outweighs the potential loss.
  • Should be a formal, documented decision by management.
  • Does not mean ignoring the risk, but rather acknowledging and tolerating it.

Memory trick: Accept, Avoid, Mitigate, Transfer: AAMT the risk.

More Risk Identification, Monitoring, and Analysis questions