Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 2 out of 14 pages
Exam (elaborations)

SEP2606 Assignment 1 Semester 2 MEMO | Due 14 August 2026

Document preview thumbnail
Preview 2 out of 14 pages

SEP2606 Assignment 1 Semester 2 MEMO | Due 14 August 2026. All questions fully answered. SECTION A QUESTION 1 After identifying the risks and security weaknesses within a client's organisation, management must select the most cost-effective risk management strategy. Discuss the four decisions available to management for managing risks cost-effectively and provide your own examples. (8)

Content preview

, PLEASE USE THIS DOCUMENT AS A GUIDE ONLY

 QUESTION 1

1. After identifying the risks and security weaknesses within a client's organisation,
management must select the most cost-effective risk management strategy. Discuss the four
decisions available to management for managing risks cost-effectively and provide your own
examples.

Management has four primary strategic options for treating risks cost-effectively: avoidance,
reduction (or modification), sharing (or transfer), and retention (or acceptance) (ISO 31000:2018,
Clause 6.5). The core of cost-effective risk management lies in selecting the option that provides the
greatest risk reduction for the resources invested, balancing the cost of treatment against the potential
financial impact of the risk itself (Hillson, 2009, p. 87).

Risk avoidance is the most definitive decision, aiming to completely eliminate the risk by ceasing or
not starting the activity that gives rise to it. According to the Institute of Risk Management (IRM,
2002, p. 9), this strategy is best suited for situations where the potential negative impact of a risk is
unacceptably high, making the cost of any other form of treatment economically unviable. For
example, a company may decide against entering a new, highly volatile international market after a
thorough risk assessment identifies significant political and financial risks that could threaten its
stability. Similarly, an organisation might terminate a project to transfer sensitive data to a new cloud
service provider upon discovering that the move would expose it to an unacceptably high risk of
cyber-attack, effectively choosing to avoid the risk altogether rather than attempt to control it
(Hopkin, 2018, p. 156).

Risk reduction, also known as modification, involves implementing controls and measures to lower
the probability of a risk occurring or to minimise its potential impact. As noted by the Committee of
Sponsoring Organizations of the Treadway Commission (COSO, 2017, p. 64), this is often the most
common and practical risk management strategy, and cost-effectiveness is achieved by focusing on
the most critical risks where intervention can have the greatest effect. For example, a logistics
company could invest in a fatigue management system for its drivers, implementing mandatory rest
breaks and monitoring technology. While this incurs a cost, it is significantly less than the potential
financial and reputational damage from a major accident caused by driver fatigue. In a more complex
scenario, a chemical plant might evaluate the cost-effectiveness of different protection plans, such as
fireproofing versus video motion detection systems, to determine which provides the best security
and safety for its investment (Hillson, 2009, p. 92).

Risk sharing involves transferring a portion of the financial or operational burden of a risk to a third
party, most commonly through insurance contracts or outsourcing arrangements (IRM, 2002, p. 11).
Hopkin (2018, p. 160) emphasises that this strategy does not eliminate the risk, nor does it absolve
the organisation of its ultimate accountability, but it distributes the financial consequences. For
instance, a business can purchase professional indemnity insurance to protect against the cost of legal
claims arising from its services. The decision to share risk is cost-effective when the premium for
transferring the risk is less than the cost of the potential loss the business would have to bear itself.
Another example is using outsourcing for non-core activities; a company might contract a specialised
cybersecurity firm to manage its IT security, thereby sharing the operational and technical risk of a
data breach with experts (COSO, 2017, p. 71).

Connected book
 image
Publisher: 2010 ISBN: 9780230298996 Edition: Unknown

Document information

Uploaded on
August 9, 2026
Number of pages
14
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$4.84

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Aimark94
4.2
(643)
Sold
7454
Followers
3176
Items
2232
Last sold
2 hours ago

Reviews from verified buyers




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions