An enterprise risk manager is evaluating proposed risk responses for a legacy payment processing database with an Asset Value () of . A quantitative risk assessment established an Exposure Factor () of and an Annual Rate of Occurrence () of . To address the identified vulnerabilities, the leadership team executes two initiatives:
1. Decommissioning the legacy database completely and migrating its functionality to a managed SaaS platform to remove internal system exposure.
2. Executing a contract with an external service vendor that includes explicit financial indemnification clauses in the event of data breaches during transit.
Which TWO of the following statements accurately characterize these risk management responses and associated metrics?
- Decommissioning the legacy database represents Risk Avoidance by completely removing internal exposure to the legacy system vulnerabilities.Cevap
- Establishing contractual financial indemnification clauses with the external vendor represents Risk Transference.Cevap
- CThe pre-initiative Annual Loss Expectancy () for the legacy payment processing database was .
- DDecommissioning the legacy database functions as a deterrent security control by discouraging threat actors from targeting the organization.