CRISC Certified in Risk and Information Systems ControlIT Risk AssessmentMedium
A financial services organization is assessing the risks associated with its new cloud-based customer relationship management (CRM) system. One identified risk is 'unauthorized access to sensitive customer data due to a misconfigured cloud storage bucket.' The risk team is trying to determine the most effective mitigation strategy for this specific risk. Which of the following risk response strategies is MOST appropriate for directly addressing this scenario?
- ARisk Transfer
- BRisk Avoidance
- CRisk Mitigation
- DRisk Acceptance
Show answer & explanationAnswer & explanation
Correct answer: C. Risk Mitigation
The scenario describes a specific vulnerability (misconfigured cloud storage) leading to a potential impact (unauthorized data access). Risk mitigation involves implementing controls or actions to reduce the likelihood or impact of such an event, which directly addresses the misconfiguration.
Why the other options are wrong
- A. Risk transfer involves shifting the financial burden of the risk to a third party (e.g., insurance), but it does not directly prevent the misconfiguration or the data breach itself.
- B. Risk avoidance would mean not using the cloud-based CRM system at all, which is often not a practical or desirable solution for a specific configuration issue.
- D. Risk acceptance means acknowledging the risk and taking no action, which is inappropriate for a known vulnerability leading to sensitive data exposure.
Risk Mitigation
Risk mitigation involves implementing controls or actions to reduce the likelihood, impact, or both, of an identified risk.
- Aims to reduce exposure to a risk.
- Often involves implementing security controls, process changes, or training.
- Most common and proactive risk response strategy.
Memory trick: MAPS help us Respond to Risks: Mitigate, Accept, Plan, Share (Transfer).