ISFS · Question #31
In the organization where you work, information of a very sensitive nature is processed. Management is legally obliged to implement the highest-level security measures. What is this kind of risk…
The correct answer is B. Risk avoiding. Risk avoidance (B) is correct because management is legally required to implement the highest-level security measures, meaning they must eliminate or prevent any possibility of the risk occurring - not merely tolerate or reduce it. When sensitive data carries legal obligations…
Question
In the organization where you work, information of a very sensitive nature is processed. Management is legally obliged to implement the highest-level security measures. What is this kind of risk strategy called?
Options
- ARisk bearing
- BRisk avoiding
- CRisk neutral
How the community answered
(28 responses)- A18% (5)
- B71% (20)
- C11% (3)
Explanation
Risk avoidance (B) is correct because management is legally required to implement the highest-level security measures, meaning they must eliminate or prevent any possibility of the risk occurring - not merely tolerate or reduce it. When sensitive data carries legal obligations, the organization cannot afford to accept any exposure.
Why the distractors are wrong:
- A (Risk bearing/acceptance): This means consciously accepting a risk and its potential consequences, which is the opposite of what's required when legal mandates demand maximum protection.
- C (Risk neutral): This describes a stance of indifference toward risk - neither actively avoiding nor actively seeking it - which falls short of the legally mandated highest-level response.
Memory tip: Think of "avoid" as "zero tolerance." When the law says maximum security, the strategy is to make the risk disappear entirely - avoidance. If you can still face the consequences, you haven't avoided the risk, you've only managed it.
Topics
Community Discussion
No community discussion yet for this question.