ISC2 CISSP (Certified Information Systems Security Professional)Security and Risk ManagementEasy

A small non-profit organization relies heavily on donor data, which includes sensitive financial and personal information. The organization has limited IT staff and budget. They decide to implement basic security controls, such as strong passwords and antivirus software, and also purchase cyber liability insurance to cover potential data breaches. This approach best characterizes which of the following risk management strategies?

  1. ARisk Avoidance
  2. BRisk Acceptance
  3. CRisk Transference
  4. DRisk Mitigation
Show answer & explanation

Correct answer: D. Risk Mitigation

The organization is implementing security controls (strong passwords, antivirus) to reduce the likelihood or impact of risks, which is risk mitigation. Additionally, purchasing insurance is a form of risk transference. Since both are present, and mitigation is a primary action, the overall strategy is best described as a combination, but the question asks what it 'best characterizes', and mitigation (reducing risk) is a core action. If 'Risk Treatment' were an option, it would be better, but among the given, mitigation is the most direct action.

Why the other options are wrong

  • A. Risk avoidance means eliminating the activity that causes the risk.
  • B. Risk acceptance means acknowledging the risk and taking no action to reduce it.
  • C. Risk transference involves shifting the financial impact of risk to another party (e.g., insurance).

Risk Mitigation

The process of reducing the likelihood or impact of a risk event through the implementation of controls and countermeasures.

  • Most common risk response strategy.
  • Involves technical, administrative, and physical controls.
  • Aims to bring residual risk to an acceptable level.

Memory trick: Avoid it, Transfer it, Accept it, or Mitigate it.

More Security and Risk Management questions