Cisco Certified Support Technician (CCST) CybersecurityRisk ManagementMedium

A software development company is adopting a DevSecOps approach. As part of this, security scans are integrated directly into the continuous integration/continuous deployment (CI/CD) pipeline. Developers receive immediate feedback on security vulnerabilities in their code, allowing them to fix issues before deployment. This proactive measure is an example of which risk management strategy?

  1. ARisk Mitigation
  2. BRisk Avoidance
  3. CRisk Transfer
  4. DRisk Acceptance
Show answer & explanation

Correct answer: A. Risk Mitigation

Integrating security scans into the CI/CD pipeline and fixing vulnerabilities before deployment is a proactive measure designed to reduce the likelihood and impact of security incidents. This directly aligns with the definition of risk mitigation, which aims to reduce risk.

Why the other options are wrong

  • B. Risk avoidance would mean not developing the software at all.
  • C. Risk transfer involves shifting the risk to another party, like an insurer.
  • D. Risk acceptance means choosing to do nothing about the risk.

Risk Mitigation

A risk management strategy that involves implementing controls and countermeasures to reduce the likelihood of a risk event occurring or to lessen its impact if it does occur.

  • Focuses on reducing risk through controls.
  • Can involve technical, administrative, or physical controls.
  • Is often the most common and practical strategy.

Memory trick: Mitigation is like putting on a seatbelt, reducing harm.

More Risk Management questions