CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingHard

An organization relies on a legacy system for critical business operations. A recent vulnerability assessment identified several high-risk vulnerabilities that cannot be fully patched due to vendor discontinuation and system instability concerns. The business unit manager, who is the risk owner, decides to continue operating the system, implementing compensating controls such as network segmentation and enhanced monitoring, and explicitly documenting the remaining risks and acceptance by senior management. This approach BEST exemplifies which of the following?

  1. ARisk Mitigation with residual acceptance.
  2. BRisk Avoidance with mitigation.
  3. CRisk Acceptance with mitigation.
  4. DRisk Transfer with acceptance.
Show answer & explanation

Correct answer: A. Risk Mitigation with residual acceptance.

The primary action is implementing compensating controls (network segmentation, enhanced monitoring) to reduce the risk, which is mitigation. However, since the system cannot be fully patched and documentation of 'remaining risks' is done, it explicitly acknowledges that some residual risk still exists and is accepted by management. This combination is best described as Risk Mitigation with residual acceptance.

Why the other options are wrong

  • B. Risk avoidance would mean discontinuing the use of the legacy system, which is not the case.
  • C. While 'Risk Acceptance with mitigation' is plausible, 'Risk Mitigation with residual acceptance' is more precise. Mitigation is the active strategy to reduce the risk, and then the remaining risk is accepted.
  • D. Risk transfer is not mentioned (e.g., insurance), and while acceptance is present, it's residual after mitigation.

Risk Mitigation with Residual Acceptance

A combined risk response strategy where active measures are taken to reduce a risk's likelihood or impact (mitigation), and any remaining risk after these measures are applied is formally acknowledged and accepted by management.

  • Involves actively reducing risk through controls.
  • Acknowledges that some risk will always remain.
  • Formal acceptance of residual risk is a critical governance step.
  • Common when risks cannot be fully eliminated or transferred.

Memory trick: Mitigate What You Can, Accept What Remains, Document It All.

More Risk Response and Reporting questions