Risk Management
Explain elements of the risk management process
What you will learn
- Explain risk as a function of likelihood and impact, not either alone.
- Name the four treatment strategies and when each is chosen.
- Separate risk tolerance from risk appetite.
- Explain business impact analysis and the numbers it produces.
NIST defines risk as a measure of the extent to which an entity is threatened by a potential circumstance or event, and a function of the adverse impact if it occurs and the likelihood of occurrence. The practical consequence: high likelihood with trivial impact is not a priority, and catastrophic impact with near-zero likelihood is not one either. The priority is where the two meet.
The risk management cycle
Identification
What risks exist at all? What is not known cannot be managed.
Assessment and analysis
How likely and how severe — qualitatively on a high/medium/low scale, or quantitatively in money.
Recording in the register
The risk register: a living list of every risk, its owner, its rating, and what was decided about it.
Choosing the strategy
Mitigate, transfer, avoid, or accept.
Monitoring and reassessment
Risk changes: last year's rating may not describe today.
The four treatment strategies
| Mitigate | Reducing likelihood or impact with a control: patching, encryption, training. The commonest. |
|---|---|
| Transfer | Moving the financial impact to another party: insurance, or a contract clause. The risk does not vanish — who pays changes. |
| Avoid | Stopping the activity that causes it: cancelling the feature, or not entering the market. |
| Accept | A conscious, documented decision to do nothing, because treatment costs more than the impact. Acceptance is a decision, not neglect. |
Transfer does not remove the risk
Insurance covers the financial loss; it does not prevent the breach, restore your reputation, or discharge your regulatory obligation. The same goes for handing a service to a supplier: accountability to the customer and the regulator stays with you. Any option saying insurance "resolves" the risk is wrong.
Risk appetite vs risk tolerance
| Appetite | Tolerance | |
|---|---|---|
| What it is | How much risk the organisation seeks in pursuit of opportunity | The acceptable deviation from that level |
| Orientation | Strategic and forward-looking | Operational, a boundary |
| Example | "We accept high risk in new products" | "But no more than two hours' downtime a month" |
Quantitative analysis and impact
| BIA | Business impact analysis: NIST defines it as the process of analysing operational functions and the effect a disruption might have on them. Recovery objectives are derived from it. |
|---|---|
| SLE | The loss expected from a single incident. |
| ARO | How many times a year the incident is expected. |
| ALE | Annualised loss expectancy = SLE × ARO. Compared against the control's cost to judge whether it is worth it. |
| Risk register | The register holding all of it: the risk, its owner, its rating, its strategy and its status. |
Real-world example: when acceptance is correct
The risk that an internal meeting-room booking server fails. A single incident is valued at two thousand riyals in disruption and lost productivity, expected twice a year — an annualised loss of four thousand. A high-availability solution costs forty-five thousand a year. The correct decision here is to accept the risk, not because the team is careless but because the cure costs eleven times the damage. But the acceptance must be recorded in the risk register under a named owner — that documentation is the only thing separating acceptance from neglect.
What matters on the exam
- Risk is a function of likelihood and impact together. An option naming only one is not a risk assessment.
- "We bought insurance" = transfer. "We cancelled the service" = avoid. "We added a control" = mitigate. "We documented and did nothing" = accept.
- Acceptance is correct when treatment costs more than the impact — provided it is documented and has an owner.
- The business impact analysis precedes the recovery plan: the time and point objectives are derived from it, not the reverse.
Quick check
Answer in your head first, then reveal.
A company buys cyber insurance. Which strategy, and what has not changed?Reveal the answer
Transfer. Nothing has changed in the likelihood of a breach, in its regulatory accountability, or in the reputational impact — the only change is who absorbs the financial loss.
A single incident costs 10,000 and occurs twice a year. What is the ALE, and is an 8,000/year control worth it?Reveal the answer
ALE = 10,000 × 2 = 20,000 a year. An 8,000 control nets a saving of 12,000, so it is justified. The rule: a control is worth it when it costs less than the annualised loss it prevents.
What separates accepting a risk from neglecting it?Reveal the answer
Documentation and an owner. Acceptance is a conscious decision recorded in the risk register with who made it and why, and reviewed periodically. Neglect is the absence of any decision.
What does a business impact analysis produce that the recovery team needs?Reveal the answer
A ranking of functions by criticality and the effect of each one's disruption over time — from which the recovery time and point objectives are derived. Without it those objectives are invented numbers.
Sign in to track your progress on this topic.
Your next step
Read the lesson, then mark it complete
Sources
Used to verify the facts. The writing is original to Passuit.