Skip to content

ACCA Strategic Professional · Strategic Business Leader · IT systems security and control

Marlow Bank has identified that a ransomware attack on its payment system has a high impact but a low likelihood, because of strong existing preventive controls. Management decides to keep the existing controls, prepare a tested recovery plan, and take no further preventive spending. Which risk response, in the standard risk response categories, does this primarily represent?

This is acceptance of residual risk alongside mitigation. The bank retains its existing controls and a tested recovery plan, and chooses not to spend more. It has not avoided the risk by stopping the activity, nor transferred it to a third party such as an insurer.

  1. ARisk avoidance, because the bank has removed the possibility of attack
  2. BRisk acceptance of the residual risk, combined with mitigation through existing controls and contingency planningCorrect
  3. CRisk transfer, because the recovery plan passes the loss to a third party
  4. DRisk exploitation, because the bank is using the threat to gain advantage

Explanation

The bank relies on existing controls (mitigation) and chooses to tolerate the remaining residual risk, backed by contingency planning. Avoidance would mean ceasing the activity. Transfer needs a third party to bear the loss, e.g. insurance, which is not described.

Did you get it right without looking?

One question tells you little. A timed set on IT systems security and control shows your real accuracy, how long you take and where you lose marks.

More IT systems security and control questions