CAS-002 · Question #353
The Chief Information Security Officer (CISO) at a company knows that many users store business documents on public cloud-based storage; and realizes this is a risk to the company. In response, the…
The correct answer is C. Mitigate. Implementing mandatory training reduces the likelihood or impact of employees misusing cloud storage, which is a risk mitigation strategy rather than elimination, transfer, or acceptance.
Question
The Chief Information Security Officer (CISO) at a company knows that many users store business documents on public cloud-based storage; and realizes this is a risk to the company. In response, the CISO implements a mandatory training course in which all employees are instructed on the proper use of cloud-based storage. Which of the following risk strategies did the CISO implement?
Options
- AAvoid
- BAccept
- CMitigate
- DTransfer
How the community answered
(56 responses)- A4% (2)
- B7% (4)
- C88% (49)
- D2% (1)
Why each option
Implementing mandatory training reduces the likelihood or impact of employees misusing cloud storage, which is a risk mitigation strategy rather than elimination, transfer, or acceptance.
Risk avoidance would require prohibiting cloud-based storage entirely, eliminating the activity that creates the risk, which the CISO did not do.
Risk acceptance means acknowledging the risk and taking no action to reduce it; implementing training is an active control, not passive acceptance.
Risk mitigation involves taking actions to reduce the probability or impact of a risk, and mandatory security awareness training directly addresses the human behavior that causes the risk of improper cloud storage use. The risk is not eliminated (employees could still misuse cloud storage) and not transferred to another party, so it qualifies specifically as mitigation. Training is a recognized administrative control that reduces residual risk without avoiding the use of cloud storage entirely.
Risk transfer shifts the financial or operational burden of a risk to a third party, such as through cyber insurance or a contract clause, which training does not accomplish.
Concept tested: Risk management strategy - mitigation via administrative controls
Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.