nerdexam
(ISC)2

CGRC · Question #594

Risk acceptance when the external subsystem owner or service provider cannot fully meet security expectations should be based on the implementation of........ Response:

The correct answer is A. compensating controls. Otherwise, the organization may have to accept a greater degree of risk or. When an external entity cannot fully meet security expectations, risk acceptance should be based on implementing compensating controls; otherwise, the organization must accept a higher degree of risk or refuse the service.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Risk acceptance when the external subsystem owner or service provider cannot fully meet security expectations should be based on the implementation of........ Response:

Options

  • Acompensating controls. Otherwise, the organization may have to accept a greater degree of risk or
  • Bcompensating controls. Otherwise, the unorganization may have to accept a greater degree of risk
  • Ccompensating controls. Otherwise, the organization may have to reject a greater degree of risk or
  • Dcompensating controls. Otherwise, the organization may have to accept a greater degree of risk or

How the community answered

(37 responses)
  • A
    92% (34)
  • B
    3% (1)
  • D
    5% (2)

Why each option

When an external entity cannot fully meet security expectations, risk acceptance should be based on implementing compensating controls; otherwise, the organization must accept a higher degree of risk or refuse the service.

Acompensating controls. Otherwise, the organization may have to accept a greater degree of risk orCorrect

Compensating controls are alternative measures that provide a similar level of security protection when a primary control cannot be fully implemented by an external party, allowing the organization to mitigate risk or accept a reduced level of residual risk.

Bcompensating controls. Otherwise, the unorganization may have to accept a greater degree of risk

This option contains a grammatical error ('unorganization') which makes it incorrect.

Ccompensating controls. Otherwise, the organization may have to reject a greater degree of risk or

The statement suggests a choice between accepting greater risk or implementing controls, so 'reject a greater degree of risk' contradicts the typical options available when controls are insufficient.

Dcompensating controls. Otherwise, the organization may have to accept a greater degree of risk or

This option is a duplicate of the correct answer, but given the structure of multiple-choice questions, option A is the specific intended correct response.

Concept tested: Risk Management - Compensating Controls

Source: https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162020.pdf

Topics

#Risk Acceptance#Compensating Controls#Risk Treatment#Third-Party Risk

Community Discussion

No community discussion yet for this question.

Full CGRC Practice