CGRC · Question #594
Risk acceptance when the external subsystem owner or service provider cannot fully meet security expectations should be based on the implementation of........ Response:
The correct answer is A. compensating controls. Otherwise, the organization may have to accept a greater degree of risk or. When an external entity cannot fully meet security expectations, risk acceptance should be based on implementing compensating controls; otherwise, the organization must accept a higher degree of risk or refuse the service.
Question
Risk acceptance when the external subsystem owner or service provider cannot fully meet security expectations should be based on the implementation of........ Response:
Options
- Acompensating controls. Otherwise, the organization may have to accept a greater degree of risk or
- Bcompensating controls. Otherwise, the unorganization may have to accept a greater degree of risk
- Ccompensating controls. Otherwise, the organization may have to reject a greater degree of risk or
- Dcompensating controls. Otherwise, the organization may have to accept a greater degree of risk or
How the community answered
(37 responses)- A92% (34)
- B3% (1)
- D5% (2)
Why each option
When an external entity cannot fully meet security expectations, risk acceptance should be based on implementing compensating controls; otherwise, the organization must accept a higher degree of risk or refuse the service.
Compensating controls are alternative measures that provide a similar level of security protection when a primary control cannot be fully implemented by an external party, allowing the organization to mitigate risk or accept a reduced level of residual risk.
This option contains a grammatical error ('unorganization') which makes it incorrect.
The statement suggests a choice between accepting greater risk or implementing controls, so 'reject a greater degree of risk' contradicts the typical options available when controls are insufficient.
This option is a duplicate of the correct answer, but given the structure of multiple-choice questions, option A is the specific intended correct response.
Concept tested: Risk Management - Compensating Controls
Source: https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162020.pdf
Topics
Community Discussion
No community discussion yet for this question.