CS0-003 · Question #524
A Chief Information Security Officer (CISO) has decided the cost to protect an asset is greater than the cost of losing the asset. Which of the following risk management principles is the CISO…
The correct answer is A. Accept. When the cost to protect an asset is greater than the cost of losing the asset, the Chief Information Security Officer (CISO) is making a conscious decision to accept the associated risk.
Question
A Chief Information Security Officer (CISO) has decided the cost to protect an asset is greater than the cost of losing the asset. Which of the following risk management principles is the CISO following?
Options
- AAccept
- BAvoid
- CTransfer
- DMitigate
How the community answered
(26 responses)- A88% (23)
- B4% (1)
- D8% (2)
Why each option
When the cost to protect an asset is greater than the cost of losing the asset, the Chief Information Security Officer (CISO) is making a conscious decision to accept the associated risk.
Risk acceptance occurs when an organization acknowledges a risk but chooses not to take action to reduce or eliminate it, often because the cost of protection exceeds the potential loss from the risk event, making it an economically justifiable choice.
Risk avoidance involves eliminating the risk entirely, often by discontinuing the activity or process that introduces the risk.
Risk transfer involves shifting the financial burden or responsibility of a risk to a third party, typically through mechanisms like insurance or outsourcing.
Risk mitigation involves taking steps to reduce the likelihood or impact of a risk, such as implementing security controls or establishing recovery plans.
Concept tested: Risk management strategies
Source: https://learn.microsoft.com/en-us/compliance/regulatory/gdpr-risk-management-strategies
Topics
Community Discussion
No community discussion yet for this question.