CISM Certified Information Security Manager – Question0342

Which of the following is the MOST appropriate course of action when the risk occurrence rate is low but the impact is high?

A.
Risk transfer
B. Risk acceptance
C. Risk mitigation
D. Risk avoidance

Correct Answer: D