CAS-001 · Question #426
The Chief Information Security Officer (CISO) at a company knows that many users store business documents on public cloud-based storage; and realizes this is a risk to the company. In response, the…
The correct answer is C. Mitigate. Implementing mandatory security training reduces the likelihood of employees misusing cloud storage by educating them on proper practices, which is a risk mitigation strategy.
Question
The Chief Information Security Officer (CISO) at a company knows that many users store business documents on public cloud-based storage; and realizes this is a risk to the company. In response, the CISO implements a mandatory training course in which all employees are instructed on the proper use of cloud-based storage. Which of the following risk strategies did the CISO implement?
Options
- AAvoid
- BAccept
- CMitigate
- DTransfer
How the community answered
(18 responses)- B6% (1)
- C89% (16)
- D6% (1)
Why each option
Implementing mandatory security training reduces the likelihood of employees misusing cloud storage by educating them on proper practices, which is a risk mitigation strategy.
Risk avoidance would mean eliminating the activity entirely, such as blocking all access to public cloud storage services - not educating employees on how to use it properly.
Risk acceptance means acknowledging the risk and choosing to take no action; implementing a training program is an active response, not passive acceptance.
Risk mitigation involves taking action to reduce the probability or impact of a risk. By deploying mandatory training, the CISO directly addresses the risky behavior - improper cloud storage use - with a control that makes employees more aware of policy and less likely to expose sensitive data. The risk still exists but is reduced in likelihood through this corrective measure.
Risk transference shifts the financial or operational burden of a risk to a third party, such as purchasing cyber insurance - training employees does not transfer the risk to another entity.
Concept tested: Risk mitigation strategy through security awareness training
Source: https://csrc.nist.gov/glossary/term/risk_mitigation
Topics
Community Discussion
No community discussion yet for this question.