Cisco Certified Support Technician (CCST) CybersecurityRisk ManagementMedium
A cloud service provider (CSP) offers various security features, including advanced threat detection, intrusion prevention systems, and data encryption for data at rest and in transit, as part of its standard service package. By using this CSP, a small business effectively shifts some of the responsibility for maintaining these security controls to the provider. This is an example of which risk management strategy?
- ARisk Transfer
- BRisk Avoidance
- CRisk Mitigation
- DRisk Acceptance
Show answer & explanationAnswer & explanation
Correct answer: A. Risk Transfer
By leveraging a cloud service provider's security features, the small business is shifting the operational burden and expertise required for maintaining those controls to the CSP. This act of moving the responsibility for a risk to another entity is known as risk transfer.
Why the other options are wrong
- B. Risk avoidance would mean not using cloud services at all.
- C. While the CSP performs mitigation, the small business's act of choosing the CSP for this purpose is a transfer.
- D. Risk acceptance means the business would handle the risk without external help.
Risk Transfer (Outsourcing)
A risk management strategy where the financial or operational responsibility for a risk is shifted to a third party, often through insurance, contracts, or outsourcing services.
- Does not eliminate the risk, only reassigns responsibility.
- Common in cloud computing, insurance, and managed security services.
- Requires careful contract review to ensure adequate coverage.
Memory trick: Transferring risk is like handing off a hot potato.