CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingMedium

A cloud service provider (CSP) offers enterprise-grade services with built-in security features, including encryption at rest and in transit, and robust identity and access management (IAM) controls. A client organization using this CSP is able to reduce its own investment in certain security controls due to the CSP's offerings. This scenario best illustrates which aspect of risk response?

  1. ARisk Avoidance
  2. BRisk Mitigation
  3. CRisk Sharing
  4. DRisk Acceptance
Show answer & explanation

Correct answer: C. Risk Sharing

By leveraging the security controls provided by the CSP, the client organization is effectively sharing the responsibility and burden of managing certain risks with the CSP. This is a form of risk sharing, where both parties contribute to the control and management of the risk.

Why the other options are wrong

  • A. Risk avoidance would mean not using the cloud service at all.
  • B. While the client is mitigating risk, the *mechanism* by which they are doing so is by leveraging another entity's controls, which specifically points to sharing or transferring that aspect of the risk.
  • D. Risk acceptance means taking no action. The client is taking action by using the CSP's controls.

Risk Sharing (Transfer)

A risk response strategy where the burden or responsibility for a risk, or its consequences, is shared with or shifted to another party, often through contracts, partnerships, or insurance.

  • Involves another entity
  • Distributes risk responsibility
  • Does not eliminate the risk entirely

Memory trick: SHARE the load, don't carry it all!

More Risk Response and Reporting questions