CAS-002 · Question #276
The Chief Information Officer (CIO) is reviewing the IT centric BIA and RA documentation. The documentation shows that a single 24 hours downtime in a critical business function will cost the…
The correct answer is B. The company should transfer the risk. When budget prevents mitigation or compensating controls and the potential loss is too large to accept, transferring the risk through insurance is the appropriate response.
Question
The Chief Information Officer (CIO) is reviewing the IT centric BIA and RA documentation. The documentation shows that a single 24 hours downtime in a critical business function will cost the business $2.3 million. Additionally, the business unit which depends on the critical business function has determined that there is a high probability that a threat will materialize based on historical data. The CIO's budget does not allow for full system hardware replacement in case of a catastrophic failure, nor does it allow for the purchase of additional compensating controls. Which of the following should the CIO recommend to the finance director to minimize financial loss?
Options
- AThe company should mitigate the risk.
- BThe company should transfer the risk.
- CThe company should avoid the risk.
- DThe company should accept the risk.
How the community answered
(26 responses)- A4% (1)
- B81% (21)
- C12% (3)
- D4% (1)
Why each option
When budget prevents mitigation or compensating controls and the potential loss is too large to accept, transferring the risk through insurance is the appropriate response.
Mitigation requires investment in controls or replacement hardware to reduce likelihood or impact, but the CIO's budget explicitly does not allow for this.
Risk transfer shifts the financial burden of a realized threat to a third party - most commonly through cyber liability or business interruption insurance - without requiring capital investment in hardware or controls. Given a $2.3 million exposure per incident, a high probability of occurrence based on historical data, and a budget that explicitly rules out mitigation and compensating controls, insurance is the only mechanism that meaningfully limits the organization's financial loss. This makes risk transfer the correct recommendation to the finance director.
Avoiding the risk would require shutting down or eliminating the critical business function entirely, which is not a viable option given that the business depends on it.
Accepting a risk with a $2.3 million cost per incident and a historically high probability of occurrence is financially irresponsible when a cost-effective transfer mechanism such as insurance is available.
Concept tested: Risk transfer via insurance for high-impact unmitigable risk
Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf
Topics
Community Discussion
No community discussion yet for this question.