Which risk management strategy involves implementing security controls to reduce the likelihood or impact of a risk?
Risk mitigation applies controls that lower either the likelihood or the impact of a threat exploiting a vulnerability. It differs from avoidance, transference and acceptance, which respectively eliminate the activity, shift the loss, or retain the exposure.
Why this answer
Risk mitigation involves implementing security controls to reduce either the likelihood or the impact of a risk. This is the most common risk management strategy because it addresses the risk directly rather than shifting or avoiding it. Examples include patching vulnerabilities, deploying firewalls, or enforcing MFA to lower the probability of exploitation.
Exam trap
The trap here is confusing mitigation with avoidance or acceptance; candidates often pick 'avoidance' when the question mentions reducing likelihood, but avoidance means eliminating the activity altogether.
How to eliminate wrong answers
Option A is wrong because risk acceptance means acknowledging the risk and taking no action, often when the cost of mitigation exceeds the potential loss. Option C is wrong because risk avoidance means eliminating the activity or asset that introduces the risk entirely, such as discontinuing a service. Option D is wrong because risk transfer shifts the financial impact to a third party, typically through insurance or outsourcing, without reducing the likelihood or impact itself.