ExamGecko
Question list
Search
Search

List of questions

Search

Question 128 - CCAK discussion

Report
Export

While using Software as a Service (SaaS) to store secret customer information, an organization identifies a risk of disclosure to unauthorized parties. Although the SaaS service continues to be used, secret customer data is not processed. Which of the following risk treatment methods is being practiced?

A.

Risk acceptance

Answers
A.

Risk acceptance

B.

Risk transfer

Answers
B.

Risk transfer

C.

Risk mitigation

Answers
C.

Risk mitigation

D.

Risk reduction

Answers
D.

Risk reduction

Suggested answer: D

Explanation:

Risk reduction is a risk treatment approach where controls are implemented to reduce the likelihood or impact of a risk event. In this scenario, while the SaaS is still in use, the organization has chosen to limit exposure by avoiding the processing of secret customer data, thus reducing the risk of unauthorized disclosure. This aligns with ISACA's guidance in CCAK, which emphasizes limiting risk exposure by controlling data handling and processing policies, a practice that is documented in CSA's Cloud Controls Matrix (CCM) guidelines for data protection and data minimization (CSA CCM Domain DSI-05, Data Security and Information Lifecycle Management).

asked 17/11/2024
Reginald Curtis Jr
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first