An organization discovers that an old standalone web server running a critical legacy service contains severe unpatchable vulnerabilities. To eliminate the threat of an external remote compromise entirely, the security team decides to shut down and permanently decommission the server without replacing its function. Which risk response strategy has the organization applied?
- Risk avoidanceCevap
- BRisk mitigation
- CRisk transfer
- DRisk acceptance
Cevap
Risk avoidance is the strategy applied when an organization completely eliminates exposure to a risk by discontinuing the associated activity or removing the risky asset entirely.
Risk avoidance entails altering plans or operational behavior to entirely remove the risk exposure. In this scenario, permanently shutting down and decommissioning the vulnerable legacy system prevents any possibility of that system being compromised.
Adım Adım Çözüm
Anahtar Kavram
Risk Response Strategies: Avoidance vs. Mitigation vs. Transfer vs. Acceptance