ISC2 CISSP (Certified Information Systems Security Professional)Security and Risk ManagementEasy
A software development company is adopting a DevSecOps approach. As part of this, security testing and vulnerability scanning tools are integrated into the continuous integration/continuous deployment (CI/CD) pipeline. This measure aims to identify and remediate security flaws early in the development lifecycle. Which of the following risk management strategies is primarily being implemented?
- ARisk Acceptance
- BRisk Avoidance
- CRisk Mitigation
- DRisk Transfer
Show answer & explanationAnswer & explanation
Correct answer: C. Risk Mitigation
Integrating security testing and vulnerability scanning into the CI/CD pipeline is a proactive measure designed to reduce the likelihood and/or impact of security risks. This directly aligns with the definition of risk mitigation.
Why the other options are wrong
- A. Risk acceptance means acknowledging a risk and taking no action to reduce it, which is not happening here.
- B. Risk avoidance involves eliminating the risk entirely by not engaging in the activity, which is not the case as development is still ongoing.
- D. Risk transfer involves shifting the risk to another party (e.g., through insurance), which is not described.
Risk Mitigation
A risk management strategy that involves taking actions to reduce the likelihood or impact of a risk. This can include implementing security controls, policies, or procedures.
- Reduces the probability or consequence of a risk.
- Often involves implementing security controls (technical, administrative, physical).
- Aims to bring risk to an acceptable level.
Memory trick: A-A-M-T: Avoid, Accept, Mitigate, Transfer – ways to handle risk.