A multinational corporation is assessing the risk of data breaches from third-party vendors. The CISM is tasked with selecting a risk treatment strategy. The organization has a low risk appetite for data breaches. Which strategy should be prioritized?
Trap 1: Mitigate the risk by conducting regular vendor audits.
Mitigation reduces but does not eliminate risk; may still exceed appetite.
Trap 2: Transfer the risk by requiring vendors to have cyber insurance.
Insurance addresses financial impact but not the risk of breach itself.
Trap 3: Accept the risk because third-party risks are unavoidable.
Acceptance is not appropriate when risk appetite is low.
- A
Mitigate the risk by conducting regular vendor audits.
Why it fails: Mitigation reduces but does not eliminate risk; may still exceed appetite.
- B
Avoid the risk by not engaging vendors that cannot meet security requirements.
Avoidance eliminates the exposure entirely by declining vendors that fail security requirements, which directly satisfies the stated low risk appetite for data breaches. Unlike mitigation, transfer or acceptance, no residual third-party breach risk remains, making it the strongest treatment when tolerance for such incidents is minimal.
- C
Transfer the risk by requiring vendors to have cyber insurance.
Why it fails: Insurance addresses financial impact but not the risk of breach itself.
- D
Accept the risk because third-party risks are unavoidable.
Why it fails: Acceptance is not appropriate when risk appetite is low.