An organization wants to share the financial consequence of a ransomware event by purchasing cyber insurance. Which option most accurately reflects the limits of this sharing approach in an ISMS?
- A.Insurance eliminates the underlying risk so no other controls are needed
- B.Insurance converts the risk into an opportunity automatically
- C.Insurance transfers reputational and operational harm fully to the insurer
- D.Insurance can transfer some financial consequences but not the reputational, legal, or operational impacts, so other controls usually remain necessary
Why D is correct
Risk sharing through insurance can offset some financial loss but does not remove the event's likelihood or its reputational, legal, and operational consequences. Therefore complementary modification controls are normally still required.
Know someone studying for ISO 27001? Send them this one.