CAS-003 · Question #527
A financial institution's information security officer is working with the risk management officer to determine what to do with the institution's residual risk after all security controls have been…
The correct answer is A. Transfer the risk. Residual risk is the risk that remains after all security controls have been implemented. With a very low risk tolerance, simply accepting residual risk (D) is inappropriate. Mitigating further (C) is not viable since all controls are already in place. Avoidance (B) would…
Question
A financial institution's information security officer is working with the risk management officer to determine what to do with the institution's residual risk after all security controls have been implemented. Considering the institution's very low risk tolerance, which of the following strategies would be BEST?
Options
- ATransfer the risk.
- BAvoid the risk
- CMitigate the risk.
- DAccept the risk.
How the community answered
(25 responses)- A76% (19)
- B4% (1)
- C16% (4)
- D4% (1)
Explanation
Residual risk is the risk that remains after all security controls have been implemented. With a very low risk tolerance, simply accepting residual risk (D) is inappropriate. Mitigating further (C) is not viable since all controls are already in place. Avoidance (B) would require ceasing the business activity entirely, which is usually not practical. Transferring the risk - typically through cyber insurance or contractual agreements - shifts the financial liability of a potential loss to a third party, satisfying a low risk tolerance without halting operations. This is the standard strategy when controls have been exhausted and accepting residual exposure is not acceptable.
Topics
Community Discussion
No community discussion yet for this question.