When should an organization retain risks?
What should an organization consider when selecting the most appropriate risk treatment option(s)?
According to ISO 31000, what is the purpose of risk management?
According to ISO 31000, how can top management and oversight bodies demonstrate their commitment to risk management?
What is the main value of scenario analysis in risk identification?
Scenario 5:
Crestview University is a well-known academic institution that recently launched a digital learning platform to support remote education. The platform integrates video lectures, interactive assessments, and student data management. After initial deployment, the risk management team identified several key risks, including unauthorized access to research data, system outages, and data privacy concerns.
To address these, the team discussed multiple risk treatment options. They considered limiting the platform's functionality, but this conflicted with the university's goals. Instead, they chose to partner with a reputable cybersecurity firm and purchase cyber insurance. They also planned to reduce the likelihood of system outages by upgrading server capacity and implementing redundant systems. Some risks, such as occasional minor software glitches, were retained after careful evaluation because they did not significantly affect Crestview's operations.
Once the treatment options were selected, Crestview's risk management team developed a detailed risk treatment plan. They prioritized actions based on which processes carried the highest risk, ensuring cybersecurity measures were addressed first.
Based on the scenario above, answer the following question:
In Scenario 5, Crestview University focused on the highest-risk areas first when developing the risk treatment plan. Is this acceptable?
What key factors should be taken into account when making decisions between multiple options involving risk?
Which element should the organization analyze when examining its external context?
On what basis should an organization determine the acceptability of a residual risk?