CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingMedium
An organization is migrating its data center to a co-location facility. The risk practitioner is reviewing the service level agreement (SLA) with the co-location provider. The SLA specifies a guaranteed uptime of 99.999% and a maximum response time of 30 minutes for critical incidents. This contractual agreement primarily serves as a mechanism for which risk response strategy?
- ARisk Mitigation
- BRisk Acceptance
- CRisk Avoidance
- DRisk Transfer
Show answer & explanationAnswer & explanation
Correct answer: D. Risk Transfer
By outsourcing the data center operations to a co-location provider and establishing an SLA with specific performance guarantees (uptime, response times), the organization is contractually shifting some of the responsibility and financial consequences of operational risks (like downtime or slow incident response) to the provider. This is a classic example of risk transfer, where a third party assumes some portion of the risk.
Why the other options are wrong
- A. While the provider implements controls to mitigate risks, the act of using an SLA to define their responsibility and liability for performance is a transfer mechanism for the client.
- B. Risk acceptance would mean the organization bears full responsibility for downtime without recourse.
- C. Risk avoidance would mean not using a co-location facility at all.
Risk Transfer
A risk response strategy that shifts the financial consequences or responsibility for a risk to another party.
- Commonly achieved through insurance or contractual agreements.
- Does not eliminate the risk, but changes who bears the burden.
- Requires careful negotiation of terms and conditions.
Memory trick: Always Assess All Options Carefully.