CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingMedium
A software development company is migrating its entire code repository to a new cloud-based version control system. A critical risk identified is 'Data loss during migration due to unforeseen compatibility issues or human error.' The risk owner, in consultation with the CRISC practitioner, decides to implement a detailed migration plan, perform multiple test migrations with simulated data, and establish a comprehensive rollback strategy. These actions represent which of the following risk response strategies?
- ARisk Avoidance
- BRisk Mitigation
- CRisk Transfer
- DRisk Acceptance
Show answer & explanationAnswer & explanation
Correct answer: B. Risk Mitigation
Implementing a detailed plan, test migrations, and a rollback strategy are all measures designed to reduce the likelihood and/or impact of data loss during migration. This proactive approach to lessen the severity or frequency of a risk is known as risk mitigation.
Why the other options are wrong
- A. Avoidance would mean not performing the migration at all, which is not the case.
- C. Transfer would involve shifting the risk to a third party (e.g., insurance), which is not being done here.
- D. Acceptance would mean taking no action, which is contrary to the steps taken.
Risk Mitigation
A risk response strategy focused on implementing controls and measures to reduce the likelihood of a risk occurring, the impact if it does occur, or both.
- Aims to reduce exposure to the risk.
- Involves implementing various controls (preventive, detective, corrective).
- Can target both likelihood and impact.
- Often the most common risk response strategy.
Memory trick: Mitigate to Make Risks Manageable and Measurable.