CISM · Question #353
An information security manager identified that a user's laptop did not have full disk encryption enabled and recommended this be configured immediately. Which type of risk treatment was applied?
The correct answer is D. Mitigation. The recommendation to enable full disk encryption is an example of mitigation, which involves taking actions to reduce the potential impact or likelihood of a risk. In this case, enabling encryption addresses the risk of unauthorized access to sensitive data in case the laptop is
Question
An information security manager identified that a user's laptop did not have full disk encryption enabled and recommended this be configured immediately. Which type of risk treatment was applied?
Options
- AAvoidance
- BTransfer
- CAcceptance
- DMitigation
How the community answered
(28 responses)- A4% (1)
- B14% (4)
- C11% (3)
- D71% (20)
Explanation
The recommendation to enable full disk encryption is an example of mitigation, which involves taking actions to reduce the potential impact or likelihood of a risk. In this case, enabling encryption addresses the risk of unauthorized access to sensitive data in case the laptop is lost or
Topics
Community Discussion
No community discussion yet for this question.