CRISC Certified in Risk and Information Systems ControlIT Risk AssessmentMedium

A financial services organization is performing an IT risk assessment. A key finding is that several critical legacy systems are approaching end-of-life and lack vendor support for security patches. Migrating these systems to modern infrastructure is cost-prohibitive in the short term. The risk management team decides to implement compensating controls, such as network segmentation and enhanced intrusion detection, and to increase monitoring. Which risk response strategy does this BEST represent?

  1. ARisk Avoidance
  2. BRisk Acceptance
  3. CRisk Mitigation
  4. DRisk Transfer
Show answer & explanation

Correct answer: C. Risk Mitigation

Implementing compensating controls (network segmentation, enhanced intrusion detection) and increasing monitoring are actions taken to reduce the likelihood or impact of a risk event. These are classic examples of risk mitigation strategies, as they aim to lessen the severity or frequency of the risk rather than eliminate, accept, or transfer it.

Why the other options are wrong

  • A. Risk avoidance would mean discontinuing the use of the legacy systems entirely.
  • B. Risk acceptance would involve acknowledging the risk without taking additional action to reduce it.
  • D. Risk transfer would involve shifting the financial burden or responsibility to a third party, such as through insurance.

Risk Mitigation

A risk response strategy that involves taking actions to reduce the likelihood of a risk occurring or to lessen the severity of its impact.

  • Involves implementing controls and safeguards.
  • Aims to lower risk to an acceptable level.
  • Can include technical, administrative, or physical controls.

Memory trick: Always 'Avoid', 'Transfer', 'Mitigate', or 'Accept' your IT risks.

More IT Risk Assessment questions