CRISC · Question #376
A risk assessment has revealed that the probability of a successful cybersecurity attack is increasing. The potential loss could exceed the organization's risk appetite. Which of the following ould…
The correct answer is D. Review cybersecurity incident response procedures. When increasing attack probability and potential loss exceed risk appetite, reviewing and enhancing incident response procedures is the most effective immediate action to mitigate impact.
Question
A risk assessment has revealed that the probability of a successful cybersecurity attack is increasing. The potential loss could exceed the organization's risk appetite. Which of the following ould be the MOST effective course of action?
Options
- ARe-evaluate the organization's risk appetite.
- BOutsource the cybersecurity function.
- CPurchase cybersecurity insurance.
- DReview cybersecurity incident response procedures.
How the community answered
(59 responses)- A24% (14)
- B7% (4)
- C14% (8)
- D56% (33)
Why each option
When increasing attack probability and potential loss exceed risk appetite, reviewing and enhancing incident response procedures is the most effective immediate action to mitigate impact.
Re-evaluating risk appetite is a strategic decision that doesn't directly address the increased probability of attacks or reduce the actual potential loss.
Outsourcing the cybersecurity function transfers operational responsibility but doesn't inherently reduce the risk of attacks or ensure better outcomes without proper oversight and robust contracts.
Purchasing cybersecurity insurance is a risk transfer strategy that covers financial losses *after* an incident but does not reduce the probability or direct impact of the attack itself.
If the probability of an attack is increasing and potential loss exceeds risk appetite, improving cybersecurity incident response procedures is a direct and proactive control to minimize the impact and duration of successful attacks when they inevitably occur. Enhanced response procedures can significantly reduce the overall loss and bring the residual risk within the organization's acceptable limits by enabling rapid detection, containment, and recovery.
Concept tested: Risk response strategies for increasing threat
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
Topics
Community Discussion
No community discussion yet for this question.