ACCA Strategic Professional · Strategic Business Leader · IT systems security and control
Marlow Bank has identified that a ransomware attack on its payment system has a high impact but a low likelihood, because of strong existing preventive controls. Management decides to keep the existing controls, prepare a tested recovery plan, and take no further preventive spending. Which risk response, in the standard risk response categories, does this primarily represent?
This is acceptance of residual risk alongside mitigation. The bank retains its existing controls and a tested recovery plan, and chooses not to spend more. It has not avoided the risk by stopping the activity, nor transferred it to a third party such as an insurer.
- ARisk avoidance, because the bank has removed the possibility of attack
- BRisk acceptance of the residual risk, combined with mitigation through existing controls and contingency planningCorrect
- CRisk transfer, because the recovery plan passes the loss to a third party
- DRisk exploitation, because the bank is using the threat to gain advantage
Explanation
The bank relies on existing controls (mitigation) and chooses to tolerate the remaining residual risk, backed by contingency planning. Avoidance would mean ceasing the activity. Transfer needs a third party to bear the loss, e.g. insurance, which is not described.
Did you get it right without looking?
One question tells you little. A timed set on IT systems security and control shows your real accuracy, how long you take and where you lose marks.
More IT systems security and control questions
- Halden Logistics has suffered two phishing incidents this year. The board has so far treated cyber security as a technical matter for the IT…
- Lumen Telecom wants to launch an app using customer location data. Before design begins, the CIO insists on assessing privacy risks and buil…
- Altamira Bank's board states that, after a system failure, payment processing must be restored within 2 hours, and that no more than 15 minu…
- Zenith Insurance allows staff to work remotely. The risk committee proposes that access to claims data be granted only after checking user i…
- Delta Foods stores customer records on laptops used by sales staff who travel. The IT director is concerned about the consequences if a lapt…
- Zephyr Insurance needs an alternative site for its claims system. Its tolerable downtime is 4 hours and budget is limited. It rejects a hot …