Question 1 of 30
Sentinel Security Solutions, a private security firm operating under ISO 18788:2015, is contracted to provide security for a high-profile international summit. During the risk assessment phase, the team identifies a potential threat of coordinated cyber-attacks targeting the summit\'s communication infrastructure. The assessment reveals that complete mitigation of this threat would require an investment exceeding the client\'s allocated budget for cybersecurity enhancements. Considering the potential impact on the summit\'s reputation, operational continuity, and the firm\'s legal obligations under data protection laws, how should Sentinel Security Solutions determine and document its risk tolerance and acceptance levels for this specific cyber threat within the framework of ISO 31000:2018? The determination must balance cost-effectiveness, operational needs, legal compliance, and stakeholder expectations. Describe the most appropriate approach.
Establish a structured, documented process that considers strategic objectives, legal and regulatory requirements, stakeholder expectations, and defines acceptable risk tolerance levels based on potential impact and likelihood, followed by a documented and justified acceptance decision for risks exceeding tolerance, subject to periodic monitoring and review.
Primarily focus on minimizing immediate costs by accepting the cyber risk without extensive documentation, relying on the client's existing cybersecurity measures, and addressing any incidents reactively as they occur to avoid upfront expenses.
Outsource the entire cybersecurity risk management to a third-party vendor without clearly defining internal risk tolerance levels or acceptance criteria, relying solely on the vendor's assessment and mitigation strategies to reduce the firm's direct responsibility.
Set an arbitrary risk tolerance level based on historical data from unrelated security operations, and if the cyber risk exceeds this level, automatically reject the contract without exploring alternative risk treatment options or stakeholder consultation to avoid potential liability.

Preparing for ISO 18788:2015 - Management System for Private Security Operations? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free