CAS-003 · Question #872
While reviewing wire transfer procedures, the Chief Information Security Officer (CISO) of a bank discovers a flaw in the policy that can potentially allow for some wire transfers to occur without…
The correct answer is B. Mitigated risk. After a compensating control is applied to a known policy flaw, the risk that has been partially addressed but not fully eliminated is classified as mitigated risk.
Question
While reviewing wire transfer procedures, the Chief Information Security Officer (CISO) of a bank discovers a flaw in the policy that can potentially allow for some wire transfers to occur without the account owner’s consent. The CISO recommends a compensating control, which is implemented immediately by operational staff, although there is still some risk posed to the bank. Which of the following BEST describes the CISO’s new concerns about wire transfer fraud?
Options
- AResidual risk
- BMitigated risk
- CInherent risk
- DAccepted risk
How the community answered
(53 responses)- A4% (2)
- B87% (46)
- C8% (4)
- D2% (1)
Why each option
After a compensating control is applied to a known policy flaw, the risk that has been partially addressed but not fully eliminated is classified as mitigated risk.
Residual risk is the risk remaining after all planned controls including primary controls are fully in place, whereas here the focus is on the act of reducing risk via a compensating control rather than what persists after a full control framework is applied.
Mitigated risk describes risk that has been reduced through the deliberate application of a control or countermeasure - in this case the compensating control deployed by operational staff to close the policy gap. The CISO's continued concern stems from the fact that the mitigation reduced but did not fully eliminate the exposure, which is the defining characteristic of a mitigated risk state.
Inherent risk is the level of risk that exists before any controls are applied at all, which does not apply here because a compensating control has already been implemented.
Accepted risk means an organization has acknowledged a risk and chosen not to mitigate it further, which contradicts the scenario where the CISO actively recommended and deployed a compensating control.
Concept tested: Risk classification - mitigated vs inherent vs residual vs accepted
Source: https://csrc.nist.gov/glossary/term/risk_mitigation
Topics
Community Discussion
No community discussion yet for this question.