📖 What is Risk Mitigation?
Risk Mitigation involves implementing controls and countermeasures to reduce the likelihood or the impact of an identified threat. This strategy focuses on bringing the risk down to an acceptable level, often through technical solutions, policy changes, or improved employee training.
"Distinguish this from "Avoidance." Mitigation does not stop the business activity entirely; it simply makes the associated risk manageable through controls."
📚 Certification: Certified in Cybersecurity (CC)
🔑 What are the Key Concepts of Risk Mitigation?
- ▸ Administrative controls use policies and procedures, such as security awareness training, to mitigate risks by changing human behavior and organizational standards.
- ▸ Technical controls implement hardware or software solutions, like firewalls and encryption, to automatically reduce the likelihood of a successful cyber attack.
- ▸ Physical controls involve tangible barriers, such as locks and security cameras, to mitigate risks associated with unauthorized physical access to assets.
- ▸ Residual risk is the level of risk that remains after mitigation controls have been implemented; this remaining risk must be formally accepted by management.
- ▸ Defense in Depth employs multiple layers of mitigation controls so that if one security measure fails, others remain to protect the critical asset.
🎯 How does Risk Mitigation appear on the CC Exam?
You may be asked to identify the correct risk treatment strategy when a company decides to implement multi-factor authentication to reduce the risk of unauthorized account access while continuing to provide remote services.
A scenario might describe a business that refuses to stop a profitable project despite security flaws but chooses to install a Web Application Firewall to lower the risk to an acceptable level.
Expect questions that require you to distinguish between risk avoidance and mitigation, specifically when a company chooses to secure a process through controls rather than eliminating the activity entirely.
❓ Frequently Asked Questions
How does risk mitigation differ from risk transference?
Mitigation focuses on reducing the risk through internal controls, whereas transference shifts the financial or operational burden to a third party, such as through a cyber insurance policy or outsourcing.
What is the relationship between mitigation and residual risk?
Mitigation aims to lower risk, but it rarely eliminates it entirely. The risk that remains after controls are applied is called residual risk, which the organization must then formally accept.