A cloud-based SaaS organization is evaluating security management options to address vulnerabilities identified in a legacy customer authentication service. The Chief Information Security Officer (CISO) recommends deploying an inline Web Application Firewall (WAF) to filter malicious input and purchasing a cyber liability insurance policy to cover regulatory penalties and third-party losses in the event of a breach. Which of the following risk response strategies are being directly implemented through these combined actions? (Select TWO.)
- Risk MitigationAnswer
- Risk TransferenceAnswer
- CRisk Avoidance
- DRisk Acceptance
Answer
The organization is implementing Risk Mitigation by deploying a Web Application Firewall to decrease exploit probability, and Risk Transference by procuring cyber liability insurance to shift financial risk.
Risk Mitigation involves applying controls—such as technical firewall rules—to reduce risk to an acceptable level. Risk Transference involves reassigning financial risk or liability to a third party, such as an insurance carrier. Both strategies are clearly demonstrated by deploying the Web Application Firewall and purchasing cyber liability insurance.
Step-by-Step Solution
Key Concept
Risk Response Selection and Alignment