01. Risk Treatment / Risk Response Options Flashcards
Risk treatment / Risk response
Represents the actions that the organisation undertakes to reduce risk to an acceptable leve
Risk treatment
176
Risk treatment / Risk response
4 risk treament options
- Mitgation
- Transfer
- Avoidance
- Acceptance
176
Risk treatment / Risk response
Brining in an external competent firm to perform anorganisations risk assessment is the best solution to help identify…
unknown unknowns
176
Risk treatment / Risk response
In an enterprise environment, not all risks can be mitigated or eliminated because…
there are not enough resources to treat them all
177
Risk treatment / Risk response
A strategy is needed for choosing the best combination of solutions that will reduce risk by…
the greatest possible margin
177
Risk treatment / Risk response
A security manager making risk treatment decisions runs the risk of others in the organisation…
not supporting their decisions
177
Risk treatment / Risk response
A security steering committee making a decisions about risk treatment represents..
a consensus decision and often the best choice
When stakeholders are involved in risk matters, they are more likely to support decisions affecting them
177
Risk mitigation
Involves the implementation of some solution that will reduce an identified risk
Risk Mitigation
177
Risk mitigation
An orgnisation will usually make a decision about implementing some form of risk mitigation after performing a..
cost analysis to determine if the reduction of risk is worth the expenditure of risk mitigation
177
Risk mitigation
Security managers need to monitor risk mitigation activities carefully to ensure that…
they are completed as planned and not forgotten about
178
Risk mitigation
Controls and risk assessments are tightly coupled in the…
risk management lifecycle
178
Risk Transfer
The means by which some or all of the risk is transferred to some external entitiy
Risk Transfer
178
Risk Transfer
Risk trasnfer is selected when an organisation does not have the..
operational or financial capacity to accept the risk and when risk mitgiation is not the best choice
178
Risk Transfer
Risk transfer typically works with only a portion of the risk and it does not..
reduce all of the risk
179
Risk Avoidance
The process by which the organisation abandons the risk inducing activity, such as taking an asset out of service
Risk avoidance
179