CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingEasy

A financial services organization has implemented a new security awareness training program for all employees. The program includes regular phishing simulations and modules on data handling best practices. Which of the following risk response strategies does this program primarily represent?

  1. ARisk Mitigation
  2. BRisk Acceptance
  3. CRisk Avoidance
  4. DRisk Transfer
Show answer & explanation

Correct answer: A. Risk Mitigation

Security awareness training and phishing simulations are designed to reduce the likelihood or impact of security incidents, which is a core component of risk mitigation. They do not eliminate the risk, accept it passively, avoid the activity, or shift it to another party.

Why the other options are wrong

  • B. Risk acceptance involves consciously deciding to take no action to reduce the risk.
  • C. Risk avoidance involves eliminating the activity that gives rise to the risk.
  • D. Risk transfer shifts the financial or operational responsibility of a risk to a third party.

Risk Mitigation

A risk response strategy that involves taking actions to reduce the likelihood or impact of a risk event.

  • Aims to reduce exposure to risk.
  • Can involve implementing controls, training, or process changes.
  • Does not eliminate the risk entirely, but makes it more manageable.

Memory trick: Mitigate risks, make them less impactful.

More Risk Response and Reporting questions