During the solution architecture review, the Architecture Review Board (ARB) identifies a security risk in a proposed cloud migration project. The solution relies on a single cloud region with no disaster recovery plan. Which of the following is the BEST recommendation to mitigate this risk?
Deploying across multiple cloud regions with automated failover directly removes the single-region dependency identified by the ARB, satisfying the resilience constraint the stem raises. Unlike backup-only or manual recovery approaches, automated failover maintains service availability during a regional outage, which is the specific risk the proposed architecture currently leaves unmitigated.
Why this answer
The identified risk is the lack of disaster recovery for a single-region cloud deployment. The best mitigation is to deploy across multiple cloud regions with automated failover, which directly addresses the availability and resilience gap by ensuring the application survives a regional outage. This is a preventive/architectural control that reduces both likelihood and impact of downtime.
Exam trap
CRISC often tests the difference between risk mitigation, risk transfer, and risk assessment — candidates select insurance (transfer) or BIA (assessment) when the question asks for the BEST recommendation to mitigate an availability risk, which requires a preventive architectural control.
How to eliminate wrong answers
Option B is wrong because cyber insurance is a financial risk transfer mechanism — it compensates losses after an incident but does not restore service or prevent downtime, so it does not mitigate the availability risk. Option C is wrong because encryption at rest and in transit addresses confidentiality and data protection, not availability or disaster recovery; it is irrelevant to the single-region resilience gap. Option D is wrong because a business impact analysis identifies and quantifies the consequences of disruption, but it is an assessment activity, not a mitigation — it does not reduce the risk itself.