Question

Difficulty: Very hardRisk Identification, Assessment, and Response Strategies

An enterprise risk manager is evaluating the updated organizational risk register following a infrastructure modernizing initiative. During this initiative, the cybersecurity team decommissioned several legacy database servers that contained unpatchable vulnerabilities, purchased a comprehensive cyber insurance policy to cover data breach notifications and regulatory fines, and migrated customer analytics workloads to a public Cloud Service Provider (CSP) under an Infrastructure as a Service (IaaS) arrangement. Based on this risk management scenario, which of the following statements correctly evaluate the risk response strategies and governance responsibilities? (Select TWO.)

  1. Decommissioning the legacy database servers to eliminate exposure to unpatchable software vulnerabilities represents a risk avoidance response.Answer
  2. Procuring a cyber risk insurance policy to handle potential financial liabilities and notification expenses represents a risk transfer response.Answer
  3. C
    Migrating workloads to an IaaS cloud model transfers data classification authority, overall regulatory compliance, and governance accountability entirely to the cloud service provider.
  4. D
    Implementing cloud host monitoring and provider maintenance contracts serves as a compensating technical control that completely eliminates residual risk.

Answer

The correct evaluations are that decommissioning legacy systems with unpatchable flaws constitutes risk avoidance, and purchasing cyber insurance to shift breach costs to an insurer constitutes risk transfer.
Decommissioning legacy servers eliminates the attack vector entirely, which is the textbook definition of risk avoidance. Purchasing cyber risk insurance shifts the financial burden of incident response and legal costs to an insurer, which is the definition of risk transfer.

Step-by-Step Solution

1
Analyze the action of decommissioning legacy servers with unpatchable vulnerabilities.
Discontinuing the vulnerable system removes the source of risk entirely, which aligns with Risk Avoidance.
Risk avoidance occurs when an organization alters its plans or operations to eliminate a hazard or risk exposure completely.
2
Analyze the action of purchasing a cyber insurance policy.
Shifting financial burdens and breach response costs to an insurance underwriter aligns with Risk Transfer.
Risk transfer shifts the financial or operational impact of a risk to a third party in exchange for a fee or premium.
3
Evaluate the statement regarding cloud migration and regulatory accountability under IaaS.
The statement is false because data governance and compliance remain the customer's responsibility under the shared responsibility model.
Cloud Service Providers manage underlying infrastructure security, but data ownership, privacy, and compliance always remain with the customer enterprise.
4
Evaluate the statement regarding residual risk elimination.
The statement is false because security controls reduce risk, but residual risk can never be reduced to zero.
Residual risk is the remaining risk existing after controls and safeguards are implemented.

Key Concept

Risk Response Strategies and Cloud Shared Responsibility Model
Rate this question