Cisco Certified Support Technician (CCST) CybersecurityRisk ManagementMedium

A new software development team has been formed within an organization. Due to tight deadlines, the team decides to use several open-source libraries without conducting thorough security vulnerability scans or dependency checks. This decision is consciously made, understanding the potential for introducing vulnerabilities, but accepting the risk to meet the project's timeline. Which risk response strategy does this scenario best describe?

  1. ARisk Mitigation
  2. BRisk Acceptance
  3. CRisk Transfer
  4. DRisk Avoidance
Show answer & explanation

Correct answer: B. Risk Acceptance

The scenario describes a conscious decision to proceed with an activity (using open-source libraries without full scans) despite knowing the risks, because the benefits (meeting deadlines) outweigh the perceived need for immediate risk reduction. This is a classic example of risk acceptance.

Why the other options are wrong

  • A. Risk mitigation would involve conducting the vulnerability scans or implementing other controls to reduce the risk.
  • C. Risk transfer would involve shifting the risk to a third party, such as an insurance company or a vendor, which is not happening here.
  • D. Risk avoidance would mean not using the open-source libraries at all.

Risk Acceptance

A risk response strategy where an organization consciously decides to take no action to reduce or eliminate a specific risk, often because the cost of mitigation outweighs the potential impact, or the risk is deemed low.

  • Can be passive (unaware) or active (conscious decision).
  • Often used for low-impact or low-likelihood risks.
  • Requires documentation of the decision and rationale.

Memory trick: Decide, Act, or Ignore: The three paths of risk.

More Risk Management questions