CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingMedium
A company has identified a critical vulnerability in a legacy system that processes sensitive customer data. Due to the system's age and complexity, patching is not feasible, and replacing it will take 18-24 months. The risk owner decides to implement a temporary solution involving network segmentation, enhanced logging, and continuous monitoring by a dedicated security team. This approach is an example of which risk response strategy?
- ARisk Mitigation
- BRisk Avoidance
- CRisk Acceptance
- DRisk Transfer
Show answer & explanationAnswer & explanation
Correct answer: A. Risk Mitigation
Implementing network segmentation, enhanced logging, and continuous monitoring are all actions taken to reduce the likelihood and/or impact of the identified risk (exploitation of the vulnerability). These are active measures to control the risk while a permanent solution (system replacement) is being developed, which classifies them as risk mitigation. While the underlying vulnerability remains, these controls reduce the exposure, thus mitigating the risk.
Why the other options are wrong
- B. Risk avoidance would mean ceasing to use the legacy system or the sensitive data it processes, which is not happening.
- C. Risk acceptance would imply taking no further action beyond acknowledging the risk, which is not the case here.
- D. Risk transfer would involve shifting the risk to a third party (e.g., insurance), which is not described by these technical controls.
Risk Mitigation
The process of reducing the adverse effects of a risk by implementing controls to lower its likelihood or impact.
- Involves actively managing the risk.
- Can include technical, administrative, and physical controls.
- Often a primary strategy when risks cannot be avoided or fully transferred.
Memory trick: Always Assess All Options Carefully.