nerdexam
CompTIA

CAS-003 · Question #276

The Chief Information Officer (CIO) is reviewing the IT centric BIA and RA documentation. The documentation shows that a single 24 hours downtime in a critical business function will cost the…

The correct answer is B. The company should transfer the risk. Risk transfer shifts the financial consequences of a risk to a third party - most commonly through cyber insurance, but also via outsourcing or contractual indemnification. Given the scenario constraints - the CIO cannot mitigate (no budget for compensating controls) and cannot…

Risk Management

Question

The Chief Information Officer (CIO) is reviewing the IT centric BIA and RA documentation. The documentation shows that a single 24 hours downtime in a critical business function will cost the business $2.3 million. Additionally, the business unit which depends on the critical business function has determined that there is a high probability that a threat will materialize based on historical data. The CIO's budget does not allow for full system hardware replacement in case of a catastrophic failure, nor does it allow for the purchase of additional compensating controls. Which of the following should the CIO recommend to the finance director to minimize financial loss?

Options

  • AThe company should mitigate the risk.
  • BThe company should transfer the risk.
  • CThe company should avoid the risk.
  • DThe company should accept the risk.

How the community answered

(28 responses)
  • A
    18% (5)
  • B
    64% (18)
  • C
    7% (2)
  • D
    11% (3)

Explanation

Risk transfer shifts the financial consequences of a risk to a third party - most commonly through cyber insurance, but also via outsourcing or contractual indemnification. Given the scenario constraints - the CIO cannot mitigate (no budget for compensating controls) and cannot avoid (it's a critical business function) - transfer is the only financially prudent option. Accepting the risk (D) would mean absorbing a potential $2.3M loss with high probability, which is irresponsible given the known exposure. Mitigating (A) is explicitly ruled out by the budget constraint. Avoiding (C) would mean shutting down the critical business function, which is not a viable option. Transferring the risk (e.g., purchasing cyber insurance) caps the financial liability at the cost of premiums.

Topics

#business impact analysis#risk transfer#risk treatment#budget constraints

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice