5.2c risk management strategies

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/8

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 12:04 PM on 8/17/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

9 Terms

1
New cards

Risk transference Moving risk to a different party; the classic example is cybersecurity insurance.

2
New cards

Risk acceptance The organization decides to take on the risk as-is; the most common risk management response.

3
New cards

Exemption (risk acceptance) A permanent

approved deviation from a security policy for a specific case that can't comply, e.g. unpatchable manufacturing equipment kept isolated from the network instead.

4
New cards

Exception (risk acceptance) A temporary deviation from a policy due to a specific conflict

e.g. delaying a required patch because it breaks critical software, until compatibility is resolved.

5
New cards

Risk avoidance Completely eliminating the risk by removing the activity

asset, or exposure entirely, so no ongoing risk management is needed.

6
New cards

Risk mitigation Reducing risk through a control

without eliminating it entirely, e.g. deploying an NGFW to reduce internet-based risk.

7
New cards

Four risk strategies summary Transfer: move it to someone else. Accept: keep it as-is (most common). Avoid: eliminate it entirely. Mitigate: reduce it with a control.

8
New cards

Risk reporting An ongoing

regularly updated document listing all tracked risks and how they're being handled, used by upper management for business decisions.

9
New cards

Risk reporting vs risk register The register is project-specific and detailed

with named risks and owners. Risk reporting is the broader, ongoing summary of critical and emerging risks used for leadership decisions.