Courseiva

Risk Mitigation — Technical Controls and Compensating Controls

A company is implementing a new cloud-based customer relationship management (CRM) system. The risk manager has identified that the vendor's security controls may not meet the company's requirements. Which of the following is the BEST way to address this risk?

⚠ Common exam trap

CRISC often tests the misconception that transferring risk via insurance is always the best answer, when in fact addressing the root cause through contractual controls and assurance is typically the preferred risk treatment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Include security requirements in the contract and perform regular vendor audits

The best way to address the risk that a vendor's security controls may not meet requirements is to include explicit security requirements in the contract and perform regular vendor audits. This contractual and assurance-based approach directly mitigates the risk by establishing enforceable obligations and ongoing verification. It aligns with risk management principles of treating risk through controls and monitoring rather than ignoring, transferring, or eliminating the business capability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deny the existence of the risk

    Why it's wrong here

    Denying a risk removes it from the register without reducing exposure, leaving the vendor control gap unaddressed and unreported to governance. It is tempting when a risk feels unmanageable, but denial is never a valid response; mitigation, transfer, avoidance or acceptance must be chosen instead.

  • ✗

    Purchase cyber insurance to cover potential losses

    Why it's wrong here

    Insurance compensates financial loss after an incident; it does not verify or enforce the vendor's controls, so the identified gap remains. It is tempting because cyber insurance transfers residual risk, and it would be the correct choice once controls are assessed and a quantified residual risk is formally accepted by management.

  • ✗

    Avoid using the cloud CRM system

    Why it's wrong here

    Avoidance abandons the CRM investment entirely, which is disproportionate when the gap concerns vendor controls that could be remediated contractually. It is tempting because avoidance eliminates the risk, but it suits risks whose impact is intolerable and unavoidable; here mitigation or transfer preserves the business benefit.

  • ✓

    Include security requirements in the contract and perform regular vendor audits

    Why this is correct

    Contractual security requirements establish enforceable vendor obligations, and regular audits verify ongoing compliance with those controls. This addresses the identified gap between the vendor's controls and the company's requirements through both preventive and detective measures.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

4 more ways this is tested on CRISC

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A risk assessment reveals that a legacy system has a high likelihood of failure. The system is critical and cannot be replaced immediately. The company decides to implement manual overrides and additional monitoring. This is an example of:

medium
  • A.Risk Transfer
  • ✓ B.Risk Mitigation
  • C.Risk Acceptance
  • D.Risk Avoidance

Why B: Implementing manual overrides and additional monitoring reduces the probability or impact of the legacy system failure without eliminating the risk entirely. This is the definition of risk mitigation, as it applies controls to lower the residual risk to an acceptable level while the system remains in operation.

Variation 2. Based on the exhibit, what is the primary risk response strategy demonstrated by this firewall rule?

easy
  • A.Risk Transfer
  • B.Risk Acceptance
  • ✓ C.Risk Mitigation
  • D.Risk Avoidance

Why C: The firewall rule denies inbound traffic on TCP port 443 (HTTPS) from any source to any destination. This directly reduces the attack surface by blocking a specific protocol, which is a classic risk mitigation action. By implementing a technical control to reduce the likelihood or impact of a threat, the organization is applying risk mitigation, not transferring, accepting, or avoiding the risk entirely.

Variation 3. Based on the exhibit, which risk is most likely present and what is the most appropriate risk response?

hard
  • A.Risk of cost; set a budget alert
  • ✓ B.Risk of data exposure; apply a deny rule to restrict access
  • C.Risk of availability; implement backup
  • D.No risk; the policy is standard

Why B: The exhibit shows a cloud storage access policy that allows public access via a wildcard permission with an allow effect. This directly exposes data to the internet, creating a risk of unauthorized data exposure. The most appropriate risk response is to apply a deny rule to restrict access, such as modifying the policy to remove the wildcard permission or adding conditions to block public access.

Variation 4. An organization uses a legacy system that cannot be patched because the vendor is defunct. The system supports a core business function. The risk assessment shows a high likelihood of exploitation and high impact. The board has decided to keep the system operational due to its criticality. Which risk response should the risk manager recommend?

hard
  • A.Accept the risk
  • ✓ B.Implement compensating controls
  • C.Transfer via insurance
  • D.Avoid by decommissioning

Why B: When a legacy system cannot be patched and the risk is high, compensating controls are the most appropriate response to reduce the residual risk to an acceptable level. Compensating controls, such as network segmentation, strict access controls, or an application-layer firewall, mitigate the exploitation vector without decommissioning the critical system. The board's decision to keep the system operational means avoidance is not an option, and acceptance alone would leave the organization exposed to an unacceptable risk level.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.