After a risk assessment, a security team decides to apply new security controls to a system. The goal is to lower the likelihood of an incident occurring from a known risk. Which risk management strategy is being used?
Risk mitigation is the strategy that involves implementing security controls or countermeasures to reduce risk exposure and minimize the likelihood or impact of an incident. The other options are incorrect. Risk acceptance involves acknowledging a risk and taking no action. Risk avoidance means stopping the activity that creates the risk. Risk transference involves shifting the financial impact of a risk to a third party, like an insurance company.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are security controls in risk mitigation?
Open an interactive chat with Bash
How does mitigation differ from other risk management strategies like transference or avoidance?