CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingMedium
A cloud service provider (CSP) offers enterprise-grade services with built-in security features, including encryption at rest and in transit, and robust identity and access management (IAM) controls. A client organization using this CSP is able to reduce its own investment in certain security controls due to the CSP's offerings. This scenario best illustrates which aspect of risk response?
- ARisk Avoidance
- BRisk Mitigation
- CRisk Sharing
- DRisk Acceptance
Show answer & explanationAnswer & explanation
Correct answer: C. Risk Sharing
By leveraging the security controls provided by the CSP, the client organization is effectively sharing the responsibility and burden of managing certain risks with the CSP. This is a form of risk sharing, where both parties contribute to the control and management of the risk.
Why the other options are wrong
- A. Risk avoidance would mean not using the cloud service at all.
- B. While the client is mitigating risk, the *mechanism* by which they are doing so is by leveraging another entity's controls, which specifically points to sharing or transferring that aspect of the risk.
- D. Risk acceptance means taking no action. The client is taking action by using the CSP's controls.
Risk Sharing (Transfer)
A risk response strategy where the burden or responsibility for a risk, or its consequences, is shared with or shifted to another party, often through contracts, partnerships, or insurance.
- Involves another entity
- Distributes risk responsibility
- Does not eliminate the risk entirely
Memory trick: SHARE the load, don't carry it all!