CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingHard
A manufacturing company relies heavily on its operational technology (OT) systems for production. A recent risk assessment identified a significant vulnerability in a legacy OT system that, if exploited, could halt production for an extended period. The company decides to implement an isolated network segment for this system, along with strict access controls and continuous monitoring, but acknowledges that a residual risk of disruption remains due to the system's age. Which of the following best describes the company's approach to this risk?
- ARisk Transfer and Acceptance
- BRisk Avoidance and Transfer
- CRisk Mitigation and Acceptance
- DRisk Avoidance and Mitigation
Show answer & explanationAnswer & explanation
Correct answer: C. Risk Mitigation and Acceptance
The company is implementing controls (isolated network, access controls, monitoring) to reduce the risk, which is mitigation. However, it also acknowledges that 'a residual risk of disruption remains,' indicating that the remaining risk is consciously accepted. This combination defines risk mitigation followed by acceptance of residual risk.
Why the other options are wrong
- A. Transfer is not explicitly mentioned. While residual risk is accepted, it's not the primary response to the initial risk.
- B. Avoidance means stopping the activity, which isn't happening. Transfer means shifting responsibility, also not happening.
- D. Avoidance is not occurring as the system is still in use. Mitigation is present, but not avoidance.
Risk Mitigation with Acceptance
A strategy where controls are implemented to reduce a risk, and any remaining (residual) risk is consciously acknowledged and accepted.
- Most risks cannot be fully eliminated.
- After mitigation, organizations often accept the residual risk.
- Requires a clear understanding of the remaining risk exposure.
Memory trick: Mitigate what you can, accept what's left.