組織は、クラウド技術に関連するリスクを管理するために、ITチームにクラウドセキュリティに関する特別なトレーニングを提供する計画を立てています。この対応はリスクと見なされます。
正解:B
Risk mitigation involves implementing measures to reduce either the likelihood or impact of a risk.
By providing targeted training, the organization increases staff capability, thereby reducing the likelihood of misconfigurations or compliance errors in cloud usage.
ISACA defines mitigation as:
"Implementing controls or training to reduce exposure to risk within acceptable levels."
* A Transfer = insurance or outsourcing.
* C Acceptance = no action.
* D Deferral = postponing response.
Hence, B. Mitigation is correct.
CRISC Reference: Domain 3 - Risk Response and Mitigation, Topic: Risk Response Options.