What risk treatment option has Company A implemented if it has required from its employees the change of email passwords at least once every 60 days?
What risk treatment option has Company A implemented if it has required from its employees the change of email passwords at least once every 60 days?
A is he correct answer - Risk modification , which we can also call risk reduction is when we implement controls that reduce the impact or likelihood of something happening.
Note - answer B is not correct as risk avoidance is the elimination of hazards, activities and exposures that can negatively affect an organization and its assets. Also note with answer C ...risk retention - we accept and keep the risk as after risk assesment and analysis we believe that in the event of the risk materialising or becoming an issue we can easily manage it.