ISC2 CISSP (Certified Information Systems Security Professional)Security and Risk ManagementEasy

A software development company is adopting a DevSecOps approach. As part of this, security testing and vulnerability scanning tools are integrated into the continuous integration/continuous deployment (CI/CD) pipeline. This measure aims to identify and remediate security flaws early in the development lifecycle. Which of the following risk management strategies is primarily being implemented?

  1. ARisk Acceptance
  2. BRisk Avoidance
  3. CRisk Mitigation
  4. DRisk Transfer
Show answer & explanation

Correct answer: C. Risk Mitigation

Integrating security testing and vulnerability scanning into the CI/CD pipeline is a proactive measure designed to reduce the likelihood and/or impact of security risks. This directly aligns with the definition of risk mitigation.

Why the other options are wrong

  • A. Risk acceptance means acknowledging a risk and taking no action to reduce it, which is not happening here.
  • B. Risk avoidance involves eliminating the risk entirely by not engaging in the activity, which is not the case as development is still ongoing.
  • D. Risk transfer involves shifting the risk to another party (e.g., through insurance), which is not described.

Risk Mitigation

A risk management strategy that involves taking actions to reduce the likelihood or impact of a risk. This can include implementing security controls, policies, or procedures.

  • Reduces the probability or consequence of a risk.
  • Often involves implementing security controls (technical, administrative, physical).
  • Aims to bring risk to an acceptable level.

Memory trick: A-A-M-T: Avoid, Accept, Mitigate, Transfer – ways to handle risk.

More Security and Risk Management questions