An organization concludes that a planned market expansion into a region with unstable data-protection enforcement carries unacceptable confidentiality risk, so it cancels the expansion entirely. In ISO 27005 terms, this treatment decision is best classified as:
- A.Risk modification through compensating controls
- B.Risk avoidance by deciding not to start the activity
- C.Risk retention pending further review
- D.Risk sharing with a local partner
Why B is correct
Choosing not to begin an activity that would give rise to the risk is risk avoidance. Because the activity is cancelled rather than controlled or transferred, no controls or sharing arrangement applies.
Know someone studying for ISO 27001? Send them this one.