ISC2 CISSP (Certified Information Systems Security Professional)Security and Risk ManagementHard

A small non-profit organization relies heavily on donor data, which includes sensitive financial and personal information. They have limited IT staff and budget. A recent risk assessment identified that their current data backup solution is vulnerable to ransomware and that their current incident response plan is rudimentary. The board has a very low-risk tolerance for data loss or breach. Given these constraints, which of the following actions represents the MOST pragmatic and effective next step to address this risk?

  1. AHire additional full-time cybersecurity personnel to manage and monitor their infrastructure 24/7.
  2. BInvest in a full suite of enterprise-grade security software, including advanced threat detection and prevention.
  3. CDevelop comprehensive, multi-phase threat models for all critical donor data processing systems.
  4. DImplement offsite, immutable backups and subscribe to a specialized incident response retainer service.
Show answer & explanation

Correct answer: D. Implement offsite, immutable backups and subscribe to a specialized incident response retainer service.

Given the 'low-risk tolerance for data loss or breach,' 'limited IT staff and budget,' and specifically identified issues with 'vulnerable backups' and a 'rudimentary incident response plan,' implementing offsite, immutable backups directly addresses the data loss risk (especially from ransomware) and subscribing to an incident response retainer service leverages external expertise to address the breach response gap without needing extensive internal staff or budget for a full-time team. This is pragmatic and effective for a non-profit.

Why the other options are wrong

  • A. Hiring additional full-time staff is a significant financial commitment likely outside a 'limited budget' for a small non-profit.
  • B. Enterprise-grade software can be expensive and complex to manage for limited staff, potentially exceeding budget and resource constraints.
  • C. Threat modeling is valuable for design, but addressing immediate operational vulnerabilities (backups, incident response) is more urgent given the stated risk tolerance and current issues.

Pragmatic Risk Management

Selecting risk treatment strategies that are practical, feasible, and effective given an organization's specific resources, constraints, and risk appetite.

  • Balances security needs with budget, staff, and operational realities.
  • Prioritizes actions that deliver the most impact for the least cost/effort.
  • Often involves leveraging external services or simpler, robust solutions.

Memory trick: Budget tight, risk high? Focus on vital, outsource smart, protect core.

More Security and Risk Management questions