CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingMedium

A software development company is migrating its entire code repository to a new cloud-based version control system. A critical risk identified is 'Data loss during migration due to unforeseen compatibility issues or human error.' The risk owner, in consultation with the CRISC practitioner, decides to implement a detailed migration plan, perform multiple test migrations with simulated data, and establish a comprehensive rollback strategy. These actions represent which of the following risk response strategies?

  1. ARisk Avoidance
  2. BRisk Mitigation
  3. CRisk Transfer
  4. DRisk Acceptance
Show answer & explanation

Correct answer: B. Risk Mitigation

Implementing a detailed plan, test migrations, and a rollback strategy are all measures designed to reduce the likelihood and/or impact of data loss during migration. This proactive approach to lessen the severity or frequency of a risk is known as risk mitigation.

Why the other options are wrong

  • A. Avoidance would mean not performing the migration at all, which is not the case.
  • C. Transfer would involve shifting the risk to a third party (e.g., insurance), which is not being done here.
  • D. Acceptance would mean taking no action, which is contrary to the steps taken.

Risk Mitigation

A risk response strategy focused on implementing controls and measures to reduce the likelihood of a risk occurring, the impact if it does occur, or both.

  • Aims to reduce exposure to the risk.
  • Involves implementing various controls (preventive, detective, corrective).
  • Can target both likelihood and impact.
  • Often the most common risk response strategy.

Memory trick: Mitigate to Make Risks Manageable and Measurable.

More Risk Response and Reporting questions