Risk Management Strategies
- •
def
- •
the range of formal responses an organization can take toward an identified risk
- •
- •
strategies
- •
transfer — move the risk to another party (e.g., cybersecurity insurance)
- •
accept — a business decision to simply take the risk, often the default course
- •
accept with exemption — a policy/regulation genuinely cannot be followed (e.g., due to organization size or available controls); typically needs formal approval
- •
accept with exception — an internal policy isn't applied in a specific case (e.g., a required update timeframe is relaxed because it would crash a critical package)
- •
avoid — stop participating in the high-risk activity entirely, removing the risk
- •
mitigate — invest in controls to decrease the risk level
- •
- •
risk reporting
- •
a formal document, usually for senior management, detailing identified risks (especially critical/emerging ones) to support resourcing and budgeting decisions
- •
- •
related