組織は、潜在的な罰金のコストと比較して、コントロールを実装するコストが高いため、コントロールを導入しないことにしました。次のリスク管理戦略のうち、組織が従っているものはどれですか?
正解:D
Acceptance is a risk management strategy that involves acknowledging the existence and potential impact of a risk, but deciding not to take any action to reduce or eliminate it. This strategy is usually adopted when the cost of implementing controls outweighs the benefit of mitigating the risk, or when the risk is deemed acceptable or unavoidable. In this case, the organization decided not to put controls in place because of the high cost compared to the potential fine, which means they accepted the risk. Reference: https://www.comptia.org/blog/what-is-risk-acceptance