CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingHard

A financial institution has identified a high risk of unauthorized access to its core banking systems, which could lead to significant financial losses and reputational damage. The current controls include strong passwords and basic intrusion detection. The risk committee mandates a more robust control environment. Which of the following control design principles would be MOST effective in strengthening the overall security posture against this risk?

  1. ASecurity by Obscurity
  2. BCost-effectiveness
  3. CDefense in Depth
  4. DSingle Point of Control
Show answer & explanation

Correct answer: C. Defense in Depth

Defense in Depth involves layering multiple, independent security controls to protect assets. If one control fails, others are in place to provide protection, which is crucial for a high-risk system like core banking.

Why the other options are wrong

  • A. Security by obscurity is a discredited approach that relies on hiding vulnerabilities rather than implementing strong controls, making it ineffective.
  • B. While cost-effectiveness is important, it's a consideration for control implementation, not a design principle for strengthening security against a high-impact risk.
  • D. A single point of control creates a single point of failure, which is a weakness, not a strength, in security design.

Defense in Depth

A strategy that uses multiple layers of security controls to protect assets, so if one control fails, others are still in place.

  • Layered security approach.
  • Reduces the impact of a single control failure.
  • Applies to people, technology, and operations.

Memory trick: Layer up like an onion: Defense in Depth.

More Risk Response and Reporting questions