Skip to content
All lessons
Objective 5.2Governance & Risk· 4 min read

Risk Management

Explain elements of the risk management process

What you will learn

  • Explain risk as a function of likelihood and impact, not either alone.
  • Name the four treatment strategies and when each is chosen.
  • Separate risk tolerance from risk appetite.
  • Explain business impact analysis and the numbers it produces.

NIST defines risk as a measure of the extent to which an entity is threatened by a potential circumstance or event, and a function of the adverse impact if it occurs and the likelihood of occurrence. The practical consequence: high likelihood with trivial impact is not a priority, and catastrophic impact with near-zero likelihood is not one either. The priority is where the two meet.

The risk management cycle

  1. Identification

    What risks exist at all? What is not known cannot be managed.

  2. Assessment and analysis

    How likely and how severe — qualitatively on a high/medium/low scale, or quantitatively in money.

  3. Recording in the register

    The risk register: a living list of every risk, its owner, its rating, and what was decided about it.

  4. Choosing the strategy

    Mitigate, transfer, avoid, or accept.

  5. Monitoring and reassessment

    Risk changes: last year's rating may not describe today.

The four treatment strategies

MitigateReducing likelihood or impact with a control: patching, encryption, training. The commonest.
TransferMoving the financial impact to another party: insurance, or a contract clause. The risk does not vanish — who pays changes.
AvoidStopping the activity that causes it: cancelling the feature, or not entering the market.
AcceptA conscious, documented decision to do nothing, because treatment costs more than the impact. Acceptance is a decision, not neglect.

Transfer does not remove the risk

Insurance covers the financial loss; it does not prevent the breach, restore your reputation, or discharge your regulatory obligation. The same goes for handing a service to a supplier: accountability to the customer and the regulator stays with you. Any option saying insurance "resolves" the risk is wrong.

Risk appetite vs risk tolerance

AppetiteTolerance
What it isHow much risk the organisation seeks in pursuit of opportunityThe acceptable deviation from that level
OrientationStrategic and forward-lookingOperational, a boundary
Example"We accept high risk in new products""But no more than two hours' downtime a month"

Quantitative analysis and impact

BIABusiness impact analysis: NIST defines it as the process of analysing operational functions and the effect a disruption might have on them. Recovery objectives are derived from it.
SLEThe loss expected from a single incident.
AROHow many times a year the incident is expected.
ALEAnnualised loss expectancy = SLE × ARO. Compared against the control's cost to judge whether it is worth it.
Risk registerThe register holding all of it: the risk, its owner, its rating, its strategy and its status.

Real-world example: when acceptance is correct

The risk that an internal meeting-room booking server fails. A single incident is valued at two thousand riyals in disruption and lost productivity, expected twice a year — an annualised loss of four thousand. A high-availability solution costs forty-five thousand a year. The correct decision here is to accept the risk, not because the team is careless but because the cure costs eleven times the damage. But the acceptance must be recorded in the risk register under a named owner — that documentation is the only thing separating acceptance from neglect.

What matters on the exam

  • Risk is a function of likelihood and impact together. An option naming only one is not a risk assessment.
  • "We bought insurance" = transfer. "We cancelled the service" = avoid. "We added a control" = mitigate. "We documented and did nothing" = accept.
  • Acceptance is correct when treatment costs more than the impact — provided it is documented and has an owner.
  • The business impact analysis precedes the recovery plan: the time and point objectives are derived from it, not the reverse.

Quick check

Answer in your head first, then reveal.

  1. A company buys cyber insurance. Which strategy, and what has not changed?Reveal the answer

    Transfer. Nothing has changed in the likelihood of a breach, in its regulatory accountability, or in the reputational impact — the only change is who absorbs the financial loss.

  2. A single incident costs 10,000 and occurs twice a year. What is the ALE, and is an 8,000/year control worth it?Reveal the answer

    ALE = 10,000 × 2 = 20,000 a year. An 8,000 control nets a saving of 12,000, so it is justified. The rule: a control is worth it when it costs less than the annualised loss it prevents.

  3. What separates accepting a risk from neglecting it?Reveal the answer

    Documentation and an owner. Acceptance is a conscious decision recorded in the risk register with who made it and why, and reviewed periodically. Neglect is the absence of any decision.

  4. What does a business impact analysis produce that the recovery team needs?Reveal the answer

    A ranking of functions by criticality and the effect of each one's disruption over time — from which the recovery time and point objectives are derived. Without it those objectives are invented numbers.

Sign in to track your progress on this topic.

Your next step

Read the lesson, then mark it complete