ExamGecko
Question list
Search
Search

Question 55 - IT Risk Fundamentals discussion

Report
Export

Which of the following risk response strategies involves the implementation of new controls?

A.

Mitigation

Answers
A.

Mitigation

B.

Avoidance

Answers
B.

Avoidance

C.

Acceptance

Answers
C.

Acceptance

Suggested answer: A

Explanation:

Definition and Context:

Mitigation involves taking steps to reduce the severity, seriousness, or painfulness of something, often by implementing new controls or safeguards. This can include processes, procedures, or physical measures designed to reduce risk.

Avoidance means completely avoiding the risk by not engaging in the activity that generates the risk.

Acceptance means acknowledging the risk and choosing not to act, either because the risk is deemed acceptable or because there is no feasible way to mitigate or avoid it.

Application to IT Risk Management:

In IT risk management, Mitigation often involves implementing new controls such as security patches, firewalls, encryption, user authentication protocols, and regular audits to reduce risk levels.

This aligns with the principles outlined in various IT control frameworks and standards, such as ISA 315 which emphasizes the importance of controls in managing IT-related risks.

Conclusion:

Therefore, when considering risk response strategies involving the implementation of new controls, Mitigation is the correct answer as it specifically addresses the action of implementing measures to reduce risk.

asked 18/11/2024
Adam Bednar
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first