1/8
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Risk transference Moving risk to a different party; the classic example is cybersecurity insurance.
Risk acceptance The organization decides to take on the risk as-is; the most common risk management response.
Exemption (risk acceptance) A permanent
approved deviation from a security policy for a specific case that can't comply, e.g. unpatchable manufacturing equipment kept isolated from the network instead.
Exception (risk acceptance) A temporary deviation from a policy due to a specific conflict
e.g. delaying a required patch because it breaks critical software, until compatibility is resolved.
Risk avoidance Completely eliminating the risk by removing the activity
asset, or exposure entirely, so no ongoing risk management is needed.
Risk mitigation Reducing risk through a control
without eliminating it entirely, e.g. deploying an NGFW to reduce internet-based risk.
Four risk strategies summary Transfer: move it to someone else. Accept: keep it as-is (most common). Avoid: eliminate it entirely. Mitigate: reduce it with a control.
Risk reporting An ongoing
regularly updated document listing all tracked risks and how they're being handled, used by upper management for business decisions.
Risk reporting vs risk register The register is project-specific and detailed
with named risks and owners. Risk reporting is the broader, ongoing summary of critical and emerging risks used for leadership decisions.