nerdexam
CompTIA

CAS-002 · Question #276

The Chief Information Officer (CIO) is reviewing the IT centric BIA and RA documentation. The documentation shows that a single 24 hours downtime in a critical business function will cost the…

The correct answer is B. The company should transfer the risk. When budget prevents mitigation or compensating controls and the potential loss is too large to accept, transferring the risk through insurance is the appropriate response.

Integration of Computing, Communications and Business Disciplines

Question

The Chief Information Officer (CIO) is reviewing the IT centric BIA and RA documentation. The documentation shows that a single 24 hours downtime in a critical business function will cost the business $2.3 million. Additionally, the business unit which depends on the critical business function has determined that there is a high probability that a threat will materialize based on historical data. The CIO's budget does not allow for full system hardware replacement in case of a catastrophic failure, nor does it allow for the purchase of additional compensating controls. Which of the following should the CIO recommend to the finance director to minimize financial loss?

Options

  • AThe company should mitigate the risk.
  • BThe company should transfer the risk.
  • CThe company should avoid the risk.
  • DThe company should accept the risk.

How the community answered

(26 responses)
  • A
    4% (1)
  • B
    81% (21)
  • C
    12% (3)
  • D
    4% (1)

Why each option

When budget prevents mitigation or compensating controls and the potential loss is too large to accept, transferring the risk through insurance is the appropriate response.

AThe company should mitigate the risk.

Mitigation requires investment in controls or replacement hardware to reduce likelihood or impact, but the CIO's budget explicitly does not allow for this.

BThe company should transfer the risk.Correct

Risk transfer shifts the financial burden of a realized threat to a third party - most commonly through cyber liability or business interruption insurance - without requiring capital investment in hardware or controls. Given a $2.3 million exposure per incident, a high probability of occurrence based on historical data, and a budget that explicitly rules out mitigation and compensating controls, insurance is the only mechanism that meaningfully limits the organization's financial loss. This makes risk transfer the correct recommendation to the finance director.

CThe company should avoid the risk.

Avoiding the risk would require shutting down or eliminating the critical business function entirely, which is not a viable option given that the business depends on it.

DThe company should accept the risk.

Accepting a risk with a $2.3 million cost per incident and a historically high probability of occurrence is financially irresponsible when a cost-effective transfer mechanism such as insurance is available.

Concept tested: Risk transfer via insurance for high-impact unmitigable risk

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf

Topics

#risk transfer#BIA#risk treatment#budget constraints

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice