An organization wants to share the financial consequence of a ransomware event by purchasing cyber insurance. Which option most accurately reflects the limits of this sharing approach in an ISMS?
- A.Insurance can transfer some financial consequences but not the reputational, legal, or operational impacts, so other controls usually remain necessary
- B.Insurance eliminates the underlying risk so no other controls are needed
- C.Insurance transfers reputational and operational harm fully to the insurer
- D.Insurance converts the risk into an opportunity automatically
Why A is correct
Risk sharing through insurance can offset some financial loss but does not remove the event's likelihood or its reputational, legal, and operational consequences. Therefore complementary modification controls are normally still required.
Know someone studying for ISO 27001? Send them this one.