Cisco Certified Support Technician (CCST) CybersecurityRisk ManagementMedium

A company decides to outsource its entire IT infrastructure to a third-party cloud provider. As part of the contractual agreement, the cloud provider assumes full responsibility for the security of the underlying infrastructure, including patching, maintenance, and physical security. The company retains responsibility for securing its data and applications. From the perspective of the company, what risk management strategy is primarily being applied regarding the infrastructure security?

  1. ARisk Avoidance
  2. BRisk Transfer
  3. CRisk Acceptance
  4. DRisk Reduction
Show answer & explanation

Correct answer: B. Risk Transfer

By outsourcing IT infrastructure and having the cloud provider contractually assume responsibility for its security, the company is shifting the burden and liability for those specific infrastructure risks to the third party. This is a clear example of risk transfer.

Why the other options are wrong

  • A. Risk avoidance would mean not having IT infrastructure at all, or not using a cloud provider.
  • C. Risk acceptance would mean using the cloud provider but not having them assume responsibility for infrastructure security.
  • D. Risk reduction would involve the company itself implementing controls to secure the infrastructure, which is now the provider's role.

Risk Transfer (Outsourcing)

A risk response strategy where the responsibility for certain risks, and often the associated assets or operations, is shifted to a third-party entity through contractual agreements.

  • Common in cloud computing and managed services.
  • Does not eliminate the company's overall risk, as ultimate accountability remains.
  • Requires careful vendor selection and contract negotiation.

Memory trick: Move it, Share it, Give it away: The transfer ways.

More Risk Management questions