CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingEasy
A financial institution has identified a significant risk related to unauthorized access to customer data through its online banking portal. The risk management team proposes implementing multi-factor authentication (MFA) for all login attempts. Which of the following risk responses does this action primarily represent?
- ARisk Avoidance
- BRisk Transfer
- CRisk Acceptance
- DRisk Mitigation
Show answer & explanationAnswer & explanation
Correct answer: D. Risk Mitigation
Implementing multi-factor authentication is a control designed to reduce the likelihood or impact of unauthorized access, which directly aligns with the definition of risk mitigation.
Why the other options are wrong
- A. Risk avoidance means eliminating the activity that gives rise to the risk. The institution is not eliminating online banking.
- B. Risk transfer involves shifting the financial burden or responsibility of a risk to another party, typically through insurance or outsourcing.
- C. Risk acceptance means choosing to take no action to reduce the risk. Implementing MFA is an action.
Risk Mitigation
The process of implementing controls or measures to reduce the likelihood or impact of an identified risk.
- Aims to reduce risk exposure
- Involves implementing controls
- Does not eliminate the risk entirely
Memory trick: ARM-T: Avoid, Reduce, Mitigate, Transfer