During design of a new control set, an information security manager identifies a risk whose residual level, after the controls already planned, sits clearly within the board-approved risk appetite. A project team nonetheless proposes adding a further costly preventive control to drive the risk lower still. What principle should most influence the manager's recommendation?
- AAdditional control should always be added when a credible option exists, since lower residual risk is invariably preferable for the organisation.
- BAdditional control should be selected whenever the proposing project team requests it, because the team understands its own operational exposure best.
- CAdditional control should be added if the chosen vendor can bundle it cheaply, since marginal cost makes the extra reduction effectively free to deploy.
- DAdditional control is justified only where risk exceeds appetite, so a control that drives risk below appetite without further benefit should not be selected. Correct
Why A is wrong: Driving residual risk ever lower sounds prudent, but treating more control as always better ignores cost and risk appetite, leading to spend that the business cannot justify against the benefit gained.
Why B is wrong: Deferring to the team's local knowledge is tempting, but control decisions must be governed against enterprise risk appetite and cost, not granted on request, or spending drifts beyond what the risk warrants.
Why C is wrong: A cheap bundle makes extra control look like easy value, but even low-cost controls add operational and assurance burden, and stacking control on a risk already within appetite still yields no benefit that justifies the effort.
Why D is correct: Controls exist to bring risk within appetite; once residual risk already sits within appetite, spending more to reduce it further is over-control that consumes resources without a corresponding business benefit.