ISC2 Governance, Risk and Compliance (CGRC) Practice Question
An e-commerce system subject to PCI DSS cannot currently fund the controls needed to meet the organization's risk tolerance for cardholder data theft. The system owner proposes shifting processing to a PCI-DSS-certified payment gateway that contractually assumes liability for fraud losses. Within RMF Step 6, what risk treatment is being pursued?
Transfer the risk to a third party through outsourcing and contractual liability.
Avoid the risk by discontinuing credit card transactions.
Accept the risk and document the decision in the authorization package.
Mitigate the risk by implementing compensating technical controls in house.
Moving card-processing functions to a third-party gateway that contractually accepts liability does not reduce the likelihood of a breach for the organization, nor does it eliminate the activity outright. Instead, the potential financial impact is shifted to another entity under the contract, making this a classic example of risk transfer. Accepting the risk would leave the liability with the organization, mitigation would involve adding or improving the organization's own technical controls, and avoidance would mean stopping credit-card transactions altogether.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What does PCI DSS stand for, and why is it important?
Open an interactive chat with Bash
What does ‘risk transfer’ mean in the context of RMF Step 6?
Open an interactive chat with Bash
How does using a PCI-DSS-certified payment gateway reduce an organization’s liability?
Open an interactive chat with Bash
What is PCI DSS?
Open an interactive chat with Bash
What does 'risk transfer' mean in risk management?
Open an interactive chat with Bash
What is RMF Step 6 and how does it relate to risk treatment?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
System Compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .