Comparison Table
| Option | Primary difference | Best use |
|---|---|---|
| Avoidance | Stop the risky activity | Retire a vulnerable unsupported system |
| Mitigation | Reduce likelihood or impact | Patch, segment, monitor, harden |
| Transfer | Shift financial or contractual impact | Cyber insurance, outsourcing terms |
| Acceptance | Approve residual risk | Documented owner decision within tolerance |
Exam clue: Acceptance must be explicit and authorized; informal tolerance is not governance.
How To Use It
Read the scenario for the required outcome. If the requirement is prevention, do not stop at detection. If the requirement is accountability, do not stop at authentication. If the requirement is recovery, distinguish data loss from service downtime.