An enterprise risk manager is evaluating the updated organizational risk register following a infrastructure modernizing initiative. During this initiative, the cybersecurity team decommissioned several legacy database servers that contained unpatchable vulnerabilities, purchased a comprehensive cyber insurance policy to cover data breach notifications and regulatory fines, and migrated customer analytics workloads to a public Cloud Service Provider (CSP) under an Infrastructure as a Service (IaaS) arrangement. Based on this risk management scenario, which of the following statements correctly evaluate the risk response strategies and governance responsibilities? (Select TWO.)
- Decommissioning the legacy database servers to eliminate exposure to unpatchable software vulnerabilities represents a risk avoidance response.Cevap
- Procuring a cyber risk insurance policy to handle potential financial liabilities and notification expenses represents a risk transfer response.Cevap
- CMigrating workloads to an IaaS cloud model transfers data classification authority, overall regulatory compliance, and governance accountability entirely to the cloud service provider.
- DImplementing cloud host monitoring and provider maintenance contracts serves as a compensating technical control that completely eliminates residual risk.
Cevap
The correct evaluations are that decommissioning legacy systems with unpatchable flaws constitutes risk avoidance, and purchasing cyber insurance to shift breach costs to an insurer constitutes risk transfer.
Decommissioning legacy servers eliminates the attack vector entirely, which is the textbook definition of risk avoidance. Purchasing cyber risk insurance shifts the financial burden of incident response and legal costs to an insurer, which is the definition of risk transfer.
Adım Adım Çözüm
Anahtar Kavram
Risk Response Strategies and Cloud Shared Responsibility Model