A SaaS provider identifies a risk that a misconfigured S3 bucket could expose customer data. Leadership decides to implement encryption, access logging, and bucket policies rather than transfer it to a cyber-insurance policy. Which ISO 27005 risk treatment option does this represent?
- A.Risk modification (reduction) by applying controls
- B.Risk sharing through a third party
- C.Risk retention by acceptance of the residual
- D.Risk avoidance by ceasing the activity
Why A is correct
Implementing controls such as encryption and access policies reduces the likelihood or impact of the risk, which is risk modification (reduction). Sharing would involve transferring part of the consequence to another party such as an insurer.
Know someone studying for ISO 27001? Send them this one.