Ch15 - 15.03 - Risk Mitigation Strategies Flashcards

1
Q

Risk Mitigation Strategies

A
  1. Mitigate the risk (mitigation)
  2. Accept the risk (acceptance)
  3. Transfer the risk (transference)
  4. Avoid the risk (risk avoidance)
  5. Deter the risk (deterrence)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q
  1. Mitigate the risk (mitigation)
A

The first way to deal with the risk is by mitigating it. Mitigation involves implementing a security control that protects the asset from the threat. For example, to protect against hard drive failure on the web server, you could purchase a RAID solution.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q
  1. Accept the risk (acceptance)
A

Another way to handle the risk is to accept it. Accepting the risk means that you do not implement any solution to protect against the threat because you are satisfied that the chances of the threat occurring and the impact of the threat do not warrant the cost of implementing a security control.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q
  1. Transfer the risk (transference)
A

You can also look at transferring the risk, which means you make the threat somebody else’s problem! For example, you may get insurance that helps you recover from the security incident.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q
  1. Avoid the risk (risk avoidance)
A

Risk avoidance is the idea that whatever the activity is that puts you at risk, you decide not to perform that activity any more in order to avoid the risk. For example, having an e-commerce web site to earn revenue puts you at risk of attack from sources on the Internet—you can avoid this by not selling products
online (but you also lose the revenue).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q
  1. Deter the risk (deterrence)
A

Not as common an approach to dealing with risk is to deter the risk. An example of deterring a risk is to threaten punishment (typically legal punishment) to anyone who attacks the asset—you are deterring the event from occurring.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly