The correct answer is B because the purpose of risk treatment is to bring risk within the organization’s acceptable level, based on risk appetite and risk tolerance. Risk treatment may involve mitigating, avoiding, transferring, or accepting risk. The objective is not simply to focus on inherent and residual risk as concepts, but to select and apply treatment options that reduce or manage risk to a level approved by the organization. Asset criticality is an important input because more critical assets may require stronger controls, but it is not the primary purpose of treatment. High- and medium-rated risks often receive priority, but risk treatment should still be based on business impact, likelihood, cost, risk appetite, and treatment effectiveness. Inherent and residual risk must be understood, but they describe risk before and after controls rather than the main focus of selecting treatment. CISM risk management principles emphasize that management must choose treatment options that align risk with business objectives and acceptable risk levels.
[Reference: CISM Information Risk Management; risk treatment, risk appetite, residual risk, and risk response principles., , ]
Submit