CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingMedium

A global technology company has outsourced its entire IT infrastructure to a major cloud service provider (CSP). As part of the contractual agreement, the CSP is responsible for all aspects of infrastructure security, including patching, vulnerability management, and physical security of data centers. The technology company retains responsibility for data classification and access management within its applications. This arrangement primarily demonstrates which risk response strategy for infrastructure security?

  1. ARisk Reduction
  2. BRisk Avoidance
  3. CRisk Acceptance
  4. DRisk Sharing
Show answer & explanation

Correct answer: D. Risk Sharing

By contracting with a CSP for infrastructure security, the technology company is transferring a significant portion of the risk to the provider. This is a form of risk sharing, where both parties have defined responsibilities for managing different aspects of the overall risk.

Why the other options are wrong

  • A. While the CSP's actions reduce risk, the *strategy* from the technology company's perspective is to share or transfer that responsibility, rather than directly implementing the reduction controls themselves.
  • B. Risk avoidance would mean not using IT infrastructure at all, which is not the case.
  • C. Risk acceptance means taking no action. Here, action is taken by transferring responsibility.

Risk Sharing (Transfer)

A risk response strategy where the impact or responsibility for a risk is shared with or transferred to a third party.

  • Often involves contracts, insurance, or outsourcing.
  • Reduces the direct financial or operational burden on the original entity.
  • Does not eliminate the risk, but shifts ownership.

Memory trick: ARM-S: Avoid, Reduce, Mitigate, Share, Accept

More Risk Response and Reporting questions