CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingEasy
A financial institution is implementing a new customer relationship management (CRM) system. During the risk assessment, it is identified that the system's default security settings are insufficient to protect sensitive customer data from unauthorized access, potentially leading to significant reputational damage and regulatory fines. The risk practitioner recommends configuring stricter access controls, enabling multi-factor authentication, and encrypting data at rest and in transit. Which of the following risk responses is being applied?
- ARisk Avoidance
- BRisk Sharing
- CRisk Acceptance
- DRisk Mitigation
Show answer & explanationAnswer & explanation
Correct answer: D. Risk Mitigation
Risk mitigation involves taking action to reduce the likelihood or impact of a risk. Configuring stricter access controls, enabling multi-factor authentication, and encrypting data are all actions designed to reduce the impact and likelihood of unauthorized access.
Why the other options are wrong
- A. Risk avoidance would mean not implementing the CRM system at all, which is not the scenario.
- B. Risk sharing involves transferring a portion of the risk to another party, such as through insurance, which is not the described action.
- C. Risk acceptance is choosing to bear the risk without taking action, which is contrary to the recommendations made.
Risk Mitigation
Risk mitigation involves taking actions to reduce the probability of a risk occurring or to lessen the impact if it does occur.
- Aims to reduce likelihood or impact.
- Implemented through controls, safeguards, or countermeasures.
- Often the most common risk response strategy.
Memory trick: ARM-S: Avoid, Reduce, Mitigate, Share.