ISC2 CISSP (Certified Information Systems Security Professional)Security and Risk ManagementMedium

A critical infrastructure organization relies on a Supervisory Control and Data Acquisition (SCADA) system for operational control. A recent security audit highlighted that the system, designed over 20 years ago, uses proprietary protocols that are difficult to patch and has several unaddressed vulnerabilities. Replacing the system is prohibitively expensive and would cause significant operational disruption. Due to these constraints, the organization decides to implement robust network segmentation, intrusion detection systems, and strict access controls around the SCADA network to prevent external threats from reaching it. What is the primary risk management strategy being employed?

  1. ARisk Mitigation
  2. BRisk Acceptance
  3. CRisk Transfer
  4. DRisk Avoidance
Show answer & explanation

Correct answer: A. Risk Mitigation

The organization is implementing 'robust network segmentation, intrusion detection systems, and strict access controls' to prevent external threats. These are all countermeasures designed to reduce the likelihood or impact of an attack on the vulnerable SCADA system, which is the definition of risk mitigation.

Why the other options are wrong

  • B. Risk Acceptance would mean doing nothing about the vulnerabilities, which is contrary to the actions taken.
  • C. Risk Transfer would involve shifting the risk to a third party (e.g., insurer), which is not the case.
  • D. Risk Avoidance would mean decommissioning the SCADA system, which is not happening.

Risk Mitigation (Control)

Implementing controls to reduce the likelihood or impact of a risk event.

  • Often involves technical, administrative, or physical safeguards.
  • Aims to lower risk to an acceptable level when avoidance isn't feasible.
  • Examples include patching, segmentation, encryption, and training.

Memory trick: AART for risk: Avoid it, Accept it, Reduce it, Transfer it.

More Security and Risk Management questions