Question

Difficulty: MediumRisk Identification, Assessment, and Response Strategies

An enterprise security manager is reviewing the risk register for an unpatchable legacy portal hosting sensitive customer records. To address the vulnerability, the organization decides to decommission the portal entirely and transition users to an enterprise platform. Additionally, to mitigate residual financial risk during the data migration phase, the organization purchases a cybersecurity liability policy. Which of the following risk response strategies are being directly implemented in this scenario? (Select TWO.)

  1. Risk Avoidance, by completely taking the vulnerable legacy portal out of serviceAnswer
  2. Risk Transference, by purchasing a cybersecurity liability insurance policyAnswer
  3. C
    Risk Mitigation, by reclassifying detective security controls as inline preventive controls to eliminate system flaws
  4. D
    Risk Acceptance, by calculating the Single Loss Expectancy (SLE) multiplied by the Annual Rate of Occurrence (ARO) to remove financial liability

Answer

The correct responses are Risk Avoidance (by decommissioning the legacy portal) and Risk Transference (by purchasing cybersecurity liability insurance).
Decommissioning the unpatchable system removes the exposure completely, satisfying Risk Avoidance. Securing an insurance policy transfers the monetary risk of residual data breach losses to an insurance vendor, satisfying Risk Transference.

Step-by-Step Solution

1
Analyze the action of decommissioning the unpatchable legacy portal.
Completely removing the system eliminates the activity and asset exposure driving the risk, matching Risk Avoidance.
Risk avoidance entails eliminating the exposure or shutting down the risk-bearing process entirely.
2
Analyze the action of purchasing a cybersecurity liability policy.
Purchasing insurance shifts the financial burden of potential breach losses to an insurer, matching Risk Transference.
Risk transference delegates financial responsibility or liability to a third party.

Key Concept

Risk Response Strategies (Avoidance vs. Transference)
Rate this question