CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingHard
During a quarterly risk committee meeting, the CISO presents a report indicating that the organization's residual risk for ransomware attacks remains high, despite implementing endpoint detection and response (EDR) solutions and regular backups. The committee asks for a strategy to further reduce this residual risk to an acceptable level. Which of the following strategies would be MOST appropriate for addressing high residual risk?
- AAccept the high residual risk, as some risks are unavoidable.
- BAvoid all systems and data that are susceptible to ransomware attacks.
- CTransfer the residual risk by purchasing a comprehensive cyber insurance policy.
- DRe-evaluate the effectiveness of existing controls and identify gaps.
Show answer & explanationAnswer & explanation
Correct answer: D. Re-evaluate the effectiveness of existing controls and identify gaps.
When residual risk remains high despite existing controls, the most prudent and foundational step is to first re-evaluate *why* the controls aren't achieving the desired reduction. This involves identifying gaps, control failures, or new threats, which then informs further mitigation actions.
Why the other options are wrong
- A. Accepting high residual risk without further action is generally not appropriate for significant threats like ransomware, especially if it exceeds the organization's risk appetite.
- B. Avoiding all susceptible systems/data is often impractical and could severely impact business operations, especially for a prevalent threat like ransomware.
- C. Transferring risk via insurance is a valid strategy, but it's often more effective after mitigation efforts have reduced the risk to a lower, insurable level. It doesn't address the underlying control weaknesses.
Residual Risk Response
Actions taken to manage risks that remain after initial risk mitigation efforts have been implemented.
- Can involve further mitigation, transfer, or acceptance.
- Requires continuous monitoring and reassessment.
- Aims to bring risk within acceptable levels.
Memory trick: Rethink, Re-evaluate, Respond (RRR).