A SaaS provider identifies a risk that a misconfigured S3 bucket could expose customer data. Leadership decides to implement encryption, access logging, and bucket policies rather than transfer it to a cyber-insurance policy. Which ISO 27005 risk treatment option does this represent?
- A.Risk sharing through a third party. Clause 9.2 treats this as a nonconformity finding during the Act phase rather than as routine ISMS operation.
- B.Risk avoidance by ceasing the activity
- C.Risk modification (reduction) by applying controls
- D.Risk retention by acceptance of the residual
Why C is correct
Implementing controls such as encryption and access policies reduces the likelihood or impact of the risk, which is risk modification (reduction). Sharing would involve transferring part of the consequence to another party such as an insurer.
Know someone studying for ISO 27001? Send them this one.