Cisco Certified Support Technician (CCST) CybersecurityRisk ManagementEasy
A cybersecurity analyst is evaluating a new cloud-based application that stores sensitive customer data. The analyst identifies that the application uses a third-party authentication service. What is the primary risk management concept being applied when considering the potential vulnerabilities introduced by this third-party service?
- ARisk Identification
- BRisk Transfer
- CRisk Mitigation
- DRisk Acceptance
Show answer & explanationAnswer & explanation
Correct answer: A. Risk Identification
Before any other risk management activities can occur, potential threats and vulnerabilities must be identified. Recognizing the third-party service as a potential source of vulnerability falls under risk identification.
Why the other options are wrong
- B. Risk transfer involves shifting the risk to another party, typically through insurance or contractual agreements, which is a mitigation strategy.
- C. Risk mitigation involves taking steps to reduce the likelihood or impact of a risk, which happens after identification and assessment.
- D. Risk acceptance is a decision made after risks have been identified and assessed.
Risk Identification
The process of discovering, recognizing, and describing risks that could affect an organization's assets.
- First step in risk management.
- Involves identifying threats, vulnerabilities, and assets.
- Can be qualitative or quantitative.
Memory trick: Identify, Analyze, Respond, Monitor: The four pillars of risk control.