CRISC Certified in Risk and Information Systems ControlIT Risk AssessmentEasy
During an IT risk analysis, a critical application is identified as being hosted on an outdated operating system with known vulnerabilities. The organization has acknowledged this risk but has decided to postpone patching due to budget constraints and the complexity of testing the legacy application. Which risk response strategy has the organization adopted?
- ARisk Acceptance
- BRisk Transfer
- CRisk Mitigation
- DRisk Avoidance
Show answer & explanationAnswer & explanation
Correct answer: A. Risk Acceptance
Risk acceptance occurs when an organization acknowledges a risk, understands its potential impact, but decides not to take any action to reduce it, often due to cost, complexity, or low perceived likelihood. Postponing patching due to budget constraints is a clear example of accepting the risk.
Why the other options are wrong
- B. Transfer would involve shifting the risk to a third party, e.g., through insurance.
- C. Mitigation would involve patching or implementing other controls to reduce the risk.
- D. Avoidance would mean discontinuing the use of the outdated system or the application entirely.
Risk Response Strategies
Actions taken to address identified risks, typically categorized as avoid, accept, mitigate, or transfer.
- Aims to bring risk levels within the organization's risk appetite.
- Chosen strategy depends on risk level, cost, and feasibility.
- Often involves a combination of strategies.
Memory trick: AART: Avoid, Accept, Reduce (Mitigate), Transfer.