管理者は、今後数年以内に組織のデータセンターの近くで発生する可能性のある洪水に関連する高レベルのリスクを示す情報を受け取ります。その結果、データセンターの運用を高台にある別の施設に移すことが決定されました。どのアプローチが採用されていますか?
正解:A
Explanation
The approach adopted by management in this scenario is risk avoidance. Risk avoidance is the elimination of a risk by discontinuing or not undertaking an activity that poses a threat to the organization3. By moving data center operations to another facility on higher ground, management is avoiding the potential flooding risk that could disrupt or damage the data center. Risk transfer, risk acceptance and risk reduction are other possible approaches for dealing with risks, but they do not apply in this case. References:
CISA Review Manual, 27th Edition, page 641
CISA Review Questions, Answers & Explanations Database - 12 Month Subscription