Cisco Certified Support Technician (CCST) CybersecurityRisk ManagementHard
A financial institution is implementing a new online banking portal. They are particularly concerned about meeting regulatory compliance requirements, such as PCI DSS and GDPR, which mandate specific security controls for handling sensitive customer data. In the context of risk management, ensuring adherence to these regulations is primarily an example of addressing which type of risk?
- AStrategic Risk
- BCompliance Risk
- CReputational Risk
- DOperational Risk
Show answer & explanationAnswer & explanation
Correct answer: B. Compliance Risk
PCI DSS and GDPR are regulatory frameworks. The risk of failing to meet their requirements, leading to fines, legal penalties, or business disruption, is specifically categorized as compliance risk.
Why the other options are wrong
- A. Strategic risk relates to decisions about an organization's overall strategy and its ability to achieve objectives.
- C. Reputational risk is the risk of damage to an organization's standing or public image, which can be a consequence of compliance failure but is not the primary risk being addressed by focusing on the regulations themselves.
- D. Operational risk relates to failures in internal processes, systems, or people, or external events impacting daily operations.
Compliance Risk
The risk of legal or regulatory sanctions, material financial loss, or loss of reputation an organization may suffer as a result of its failure to comply with laws, regulations, rules, or standards of best practice.
- Arises from failure to adhere to internal policies or external mandates.
- Can lead to fines, legal action, and reputational damage.
- Requires continuous monitoring and updates to policies.
Memory trick: Operations, Strategy, Compliance, Reputation: O.S.C.R. the business risks.