CAS-001 · Question #397
The Chief Information Officer (CIO) is reviewing the IT centric BIA and RA documentation. The documentation shows that a single 24 hours downtime in a critical business function will cost the…
The correct answer is B. The company should transfer the risk. The scenario presents a risk with three defining characteristics: (1) $2.3M financial impact per 24-hour downtime, (2) high probability of threat materialization based on historical data, and (3) no budget for hardware replacement or additional compensating controls. When an…
Question
The Chief Information Officer (CIO) is reviewing the IT centric BIA and RA documentation. The documentation shows that a single 24 hours downtime in a critical business function will cost the business $2.3 million. Additionally, the business unit which depends on the critical business function has determined that there is a high probability that a threat will materializebased on historical data. The CIO's budget does not allow for full system hardware replacement in case of a catastrophic failure, nor does it allow for the purchase of additional compensating controls. Which of the following should the CIO recommend to the finance director to minimize financial loss?
Options
- AThe company should mitigate the risk.
- BThe company should transfer the risk.
- CThe company should avoid the risk.
- DThe company should accept the risk.
How the community answered
(53 responses)- A21% (11)
- B60% (32)
- C8% (4)
- D11% (6)
Explanation
The scenario presents a risk with three defining characteristics: (1) $2.3M financial impact per 24-hour downtime, (2) high probability of threat materialization based on historical data, and (3) no budget for hardware replacement or additional compensating controls. When an organization cannot mitigate a high-probability, high-impact risk due to budget constraints, risk transfer - typically through cyber insurance or a contractual risk transfer agreement - is the appropriate CIO recommendation. Insurance converts an uncertain, potentially catastrophic loss into a predictable, manageable premium cost. Mitigation (A) is excluded by the budget constraint. Avoidance (C) would require ceasing the critical business function, which is not viable. Acceptance (D) would expose the organization to uncontrolled $2.3M+ losses per incident - inappropriate given the high probability and the existence of a viable transfer mechanism. Risk transfer lets the business continue operations while capping its financial exposure.
Topics
Community Discussion
No community discussion yet for this question.