1.9 Risk Management

CISSP Domain 1 ยท 1.9

Risk Management at a glance

Cybersecurity risk management is the process of identifying, understanding, prioritising and responding to risks that could affect organisational objectives.

The objective is not to eliminate every possible risk. The objective is to understand risk well enough that informed decisions can be made about what should be treated, transferred, avoided or accepted.

๐Ÿ”

Identify

Understand assets, threats, vulnerabilities and potential events.

What could happen?
๐Ÿ“Š

Assess

Estimate likelihood and potential business impact.

How serious is it?
๐Ÿ›ก๏ธ

Respond

Decide how the organisation should treat the risk.

What will we do about it?

How cybersecurity risk develops

๐Ÿ’Ž Asset โ†’ Something the organisation values
โšก Threat โ†’ Something capable of causing harm
๐Ÿ•ณ๏ธ Vulnerability โ†’ A weakness that can contribute to harm
๐Ÿ’ฅ Threat Event โ†’ The harmful scenario occurs
๐Ÿ“‰ Impact โ†’ The organisation suffers consequences
โš–๏ธ Risk โ†’ Likelihood + Impact considered together
1 Risk Management Fundamentals Asset, threat, vulnerability, exposure and risk

Asset

An asset is something that has value to the organisation.

Assets may include:

Information Applications Systems People Facilities Reputation Services Intellectual Property

Threat

A threat is a potential cause of an unwanted event that could harm an asset or organisational objective.

Adversarial

Cybercriminals, insiders, competitors or nation-state actors.

Accidental

Human mistakes, configuration errors or accidental deletion.

Technical

Hardware failure, software defects or infrastructure failure.

Environmental

Fire, flood, extreme weather or power failure.

Vulnerability

A vulnerability is a weakness that may contribute to a threat causing harm.

Vulnerabilities are not limited to software bugs.

Unpatched Software Weak Configuration Poor Process Excessive Privilege Weak Physical Security Lack of Training Single Point of Failure
Example

An internet-facing application contains a vulnerability allowing authentication to be bypassed.

A threat actor could exploit that weakness to access confidential customer information.

The vulnerability is not itself the complete risk. Risk comes from considering the scenario, likelihood and potential consequences.

Exposure

Exposure describes the organisation's potential for loss or harm associated with a risk scenario.

Do not confuse these terms

Threat = something capable of causing harm.

Vulnerability = weakness that may enable harm.

Risk = uncertainty about the consequences of the scenario, commonly considered through likelihood and impact.

โšก Threat and Vulnerability Identification Understand realistic risk scenarios

Identifying vulnerabilities without considering threats can produce a long technical list without explaining the real business risk.

Similarly, identifying threats without understanding the organisation's weaknesses gives an incomplete picture.

Weak risk statement

"The server has CVE-XXXX-XXXX."

More useful risk scenario

"An external attacker could exploit an unpatched vulnerability on the internet-facing customer portal to gain unauthorised access to customer information, potentially causing a reportable data breach and service disruption."

Think in scenarios

Useful risk discussions connect:

Threat โ†’ Vulnerability โ†’ Asset โ†’ Event โ†’ Business Impact

โœ๏ธ Writing a useful risk statement Translate technical findings into business risk

A good risk statement should communicate the event and its potential consequences clearly enough for a decision-maker to understand.

Because of...

What threat or condition exists?

There is a possibility that...

What event could occur?

Which could result in...

What business impact could follow?

Example

Because privileged accounts do not currently require MFA, there is a possibility that stolen administrator credentials could be used to access production systems, resulting in unauthorised changes, service disruption and exposure of sensitive information.

Executive communication

Security professionals should translate technical weaknesses into business consequences rather than expecting senior leaders to interpret scanner output.

2 Likelihood and Impact The two major dimensions of risk

Likelihood

Likelihood considers the chance that a relevant event or risk scenario will occur.

Factors may include:

Threat Capability Threat Intent Exposure Exploitability Existing Controls Historical Events

Impact

Impact considers the consequences if the event occurs.

Financial

Loss of revenue, fraud, recovery costs or penalties.

Operational

Loss or degradation of critical business services.

Legal / Regulatory

Potential legal obligations or regulatory consequences.

Reputational

Loss of customer or stakeholder confidence.

Safety

Potential harm to people.

Strategic

Failure to achieve important organisational objectives.

Simplified learning model

Risk is often taught using:

Risk โ‰ˆ Likelihood ร— Impact

This is a useful conceptual model, but real risk methodologies can use more sophisticated calculations, scales and contextual factors.

Simple qualitative risk matrix

Organisations commonly use qualitative scales to help prioritise risks.

Likelihood โ†“ / Impact โ†’LowMediumHigh
HighMediumHighCritical
MediumLowMediumHigh
LowLowLowMedium

Risk matrices vary between organisations. This example is illustrative, not a universal scoring model.

3 Qualitative Risk Analysis Describe risk using categories and judgement

Qualitative analysis uses descriptive ratings rather than attempting to assign exact monetary values.

Very Low Low Medium High Critical

Advantages

  • relatively quick;
  • easy for stakeholders to understand;
  • useful when precise financial data is unavailable;
  • effective for prioritising large numbers of risks.

Limitations

  • ratings may be subjective;
  • different people may interpret categories differently;
  • two "High" risks may still represent very different exposures;
  • poorly defined scales can produce inconsistent assessments.
Example

Likelihood: High

Impact: High

Overall risk: Critical

4 Quantitative Risk Analysis Estimate risk numerically

Quantitative analysis attempts to express risk using numerical values.

In traditional CISSP study material, several useful terms are commonly used for estimating financial loss.

AV โ€” Asset Value

The monetary value assigned to the asset or loss exposure being analysed.

EF โ€” Exposure Factor

The estimated percentage of asset value lost during one event.

SLE โ€” Single Loss Expectancy

Estimated financial loss from one occurrence.

ARO โ€” Annualised Rate of Occurrence

Estimated frequency of the event per year.

ALE โ€” Annualised Loss Expectancy

Estimated annual financial loss associated with the scenario.

Quantitative formulas

SLE AV ร— EF
ALE SLE ร— ARO

One Loss โ†’ SLE ยท One Year โ†’ ALE

๐Ÿงฎ Worked quantitative example AV โ†’ EF โ†’ SLE โ†’ ARO โ†’ ALE

Scenario

A business system has an estimated asset value of ยฃ500,000.

A particular incident is expected to cause approximately 20% loss if it occurs.

The incident is estimated to happen approximately once every five years.

Step 1 โ€” Asset Value

AV = ยฃ500,000

Step 2 โ€” Exposure Factor

EF = 20% = 0.20

Step 3 โ€” Single Loss Expectancy

SLE = ยฃ500,000 ร— 0.20

SLE = ยฃ100,000

Step 4 โ€” Annualised Rate of Occurrence

Once every five years = 1 รท 5

ARO = 0.2

Step 5 โ€” Annualised Loss Expectancy

ALE = ยฃ100,000 ร— 0.2

ALE = ยฃ20,000 per year

What does this help us do?

The estimate provides information that can contribute to decisions about how much it may be reasonable to spend reducing the risk.

Quantitative estimates are only as useful as their assumptions. Asset value, frequency and exposure can all contain uncertainty.

Qualitative vs Quantitative

Qualitative Low ยท Medium ยท High
Quantitative Numbers ยท Frequency ยท Financial estimates
Qualitative Usually easier and faster
Quantitative Can support financial decision-making

Qualitative = WORDS ยท Quantitative = NUMBERS

๐ŸŽฏ Risk Assessment Scope Know what you are assessing

A risk assessment needs a defined scope.

Without clear scope, important assets or dependencies may be missed and the conclusions may be misleading.

Scope may include

Organisation Business Process Application Technology Service Project Supplier Facility Data
Example

A risk assessment examines a customer-facing application but excludes the external identity provider on which all authentication depends.

The assessment may underestimate risk because a critical dependency sits outside the stated scope.
๐Ÿ›ก๏ธ Inherent and Residual Risk Before controls vs after controls
Inherent Risk

Risk considered before direct or focused management actions are applied to reduce its severity.

Think: Before controls.

Residual Risk

Risk remaining after risk responses or controls have been applied.

Think: After controls.

๐Ÿ”ฅ Inherent Risk โ†’ Risk before treatment
๐Ÿ›ก๏ธ Controls โ†’ Reduce likelihood and/or impact
โš–๏ธ Residual Risk โ†’ Risk that remains
Controls rarely reduce risk to zero

Management needs to understand the remaining residual risk and decide whether further treatment is required.

๐Ÿฝ๏ธ Risk Appetite and Risk Tolerance How much risk is the organisation prepared to take?

Risk appetite

Risk appetite describes the broad level and type of risk an organisation is willing to pursue or retain in support of its objectives.

Risk tolerance

Risk tolerance provides more specific boundaries or acceptable variation around risk-taking.

Example

An organisation may have a very low appetite for risks that could expose large quantities of regulated customer data.

It might establish specific tolerance thresholds requiring particular risk scenarios to be escalated to senior management.

Risk appetite is a business decision

Security professionals provide analysis and advice, but they should not independently decide how much enterprise risk the organisation is willing to accept.

5 Risk Response and Treatment Avoid ยท Mitigate ยท Transfer ยท Accept

Once risk has been assessed, the organisation needs to decide what to do about it.

๐Ÿšซ Avoid

Stop the activity creating the risk.

๐Ÿ›ก๏ธ Mitigate

Implement controls to reduce likelihood and/or impact.

๐Ÿค Transfer / Share

Shift or share financial or operational consequences through mechanisms such as insurance or contracts.

โœ… Accept

Make an informed decision to retain the remaining risk.

๐ŸŽฒ Risk Treatment examples See the four responses in practice

๐Ÿšซ Avoid

An organisation plans to offer a high-risk online service but decides the potential exposure outweighs its business value.

The project is cancelled.

๐Ÿ›ก๏ธ Mitigate

Privileged accounts are vulnerable to password theft.

The organisation introduces phishing-resistant MFA, stronger monitoring and privileged-access controls.

๐Ÿค Transfer

The organisation purchases cybersecurity insurance to reduce some of the financial consequences associated with certain cyber incidents.

โœ… Accept

A low-impact internal system has a minor residual risk.

Management determines that further remediation would cost far more than the risk justifies and formally accepts it.

Important: transferring risk does not make it disappear

Cyber insurance may transfer some financial consequences, but an organisation may still experience operational disruption, reputational damage, regulatory consequences and customer harm.

โœ๏ธ Risk Acceptance Acceptance should be informed and authorised

Risk acceptance does not mean:

"We haven't fixed it yet."

Doing nothing through neglect is not the same as an informed risk decision.

A sound acceptance process may include:

  • a clearly documented risk scenario;
  • likelihood and impact assessment;
  • existing controls;
  • residual risk;
  • business justification;
  • appropriate risk-owner approval;
  • review or expiry date;
  • ongoing monitoring.
Who accepts risk?

The person accepting the risk should have appropriate authority over the business consequence.

A vulnerability analyst or penetration tester should not normally accept enterprise risk simply because they discovered it.

6 Types of Security Controls What role does the control perform?
Preventive

Attempts to stop an unwanted event before it occurs.

Example: MFA.

Detective

Identifies events that have occurred or are occurring.

Example: intrusion detection or monitoring.

Corrective

Corrects a problem or reduces its effects after detection.

Example: applying a patch after identifying a vulnerability.

Deterrent

Discourages inappropriate behaviour.

Example: warning notices or visible surveillance.

Recovery

Helps restore capability after an event.

Example: restoring systems from backups.

Compensating

Provides alternative protection when the preferred control cannot be implemented.

Control function memory aid

Preventive STOP it
Detective FIND it
Corrective FIX it
Recovery RESTORE it
๐Ÿงฑ Control implementation categories Administrative ยท Technical ยท Physical
Administrative / Managerial

Policies, governance, risk-management processes, training and organisational procedures.

Technical / Logical

Technology-based controls such as authentication, encryption, firewalls and monitoring.

Physical

Controls protecting facilities and physical assets, such as locks, barriers and guards.

Important distinction

A control can have both a type and a function.

For example, a locked data-centre door may be a physical preventive control.

7 Control Assessments Having a control is not enough

Risk management should consider whether security and privacy controls are properly implemented and operating as intended.

A control assessment may examine:

Design

Is the control capable of addressing the risk?

Implementation

Has it actually been deployed correctly?

Operation

Is it operating consistently?

Effectiveness

Is it reducing the risk as expected?

Example

Policy requires MFA for privileged access.

MFA technology exists, but 15% of administrator accounts are excluded from enforcement.

The presence of an MFA product does not prove that the control is completely effective.
Control effectiveness changes residual risk

If an assumed control is ineffective, the organisation's real residual risk may be higher than its risk register suggests.

๐Ÿ’ฐ Cost-Benefit Considerations Security investment should be proportionate to risk

Risk treatment has a cost.

Organisations therefore need to consider whether proposed controls provide reasonable risk reduction relative to their cost and business impact.

Example

A low-value internal application produces an estimated annual loss expectancy of approximately ยฃ5,000.

A proposed dedicated security solution would cost ยฃ300,000 every year.

The organisation should consider whether a different treatment provides better value.
This does not mean "never spend more than ALE"

Risk decisions may also involve safety, legal obligations, regulatory requirements, reputational consequences and uncertainty that are not captured by a simple financial estimate.

๐Ÿ“’ Risk Register Document and track important risks

A risk register provides a structured record of identified risks and their management.

Fields might include:

Risk ID Description Asset Threat Vulnerability Likelihood Impact Risk Rating Controls Owner Treatment Residual Risk Review Date
Example risk register entry

Risk: Theft of privileged credentials could enable unauthorised production access.

Likelihood: High

Impact: High

Treatment: Implement phishing-resistant MFA and PAM.

Owner: Technology service owner.

A risk register is a management tool, not a graveyard

Risks should be reviewed, updated and actively managed rather than simply recorded once and forgotten.

๐Ÿ‘ค Risk Ownership Someone must be accountable for the risk

Identified risks should normally have an appropriate owner.

The owner should be capable of understanding and influencing the business consequences of the risk.

Example

A security consultant identifies a serious weakness in an online banking service.

The consultant can assess and communicate the risk.

The relevant business or service owner is typically better placed to own the resulting business-risk decision.
Security advises โ€” the business owns business risk

Risk ownership should reflect organisational authority and accountability.

8 Continuous Monitoring and Measurement Risk changes over time

Risk assessments represent a view of risk at a particular point in time.

Threats, vulnerabilities, controls and business conditions change.

Risk therefore needs ongoing monitoring.

Changes that may alter risk

New Vulnerability New Threat Actor Control Failure System Change Acquisition New Supplier New Regulation Incident Business Growth
Example

A vulnerability is initially considered low likelihood because no public exploit exists.

Two weeks later, reliable exploitation code becomes widely available and active attacks are observed.

The original risk assessment should be reconsidered.
๐Ÿ“ˆ Risk Measurement: KRI and KPI Know what you are measuring
KRI โ€” Key Risk Indicator

Provides information about exposure or changing risk.

KPI โ€” Key Performance Indicator

Provides information about the performance of an activity or process.

KRI example

Number of critical internet-facing vulnerabilities older than the organisation's risk threshold.

KPI example

Percentage of vulnerability-remediation tickets completed within the agreed service target.

Performance and risk are related, but not identical

A process can perform efficiently while the organisation still has significant underlying risk.

9 Risk Reporting Internal and external communication

Risk information should reach the people who need it in a form they can understand and act upon.

Internal reporting

Risk Owners CISO Management Risk Committees Executives Board

External reporting

Depending on circumstances, risk or incident information may also need to be communicated externally.

Regulators Customers Auditors Insurers Partners Authorities
Poor executive report

"There are 84,392 open CVEs."

Better risk communication

"Three critical vulnerabilities affect the service responsible for approximately 40% of online revenue. Two are internet-accessible and one has confirmed active exploitation."

Communicate consequences, not just technical data

Decision-makers need enough context to understand business exposure and make informed risk decisions.

10 Continuous Improvement Risk management should become more mature over time

Mature risk management is not a one-time annual assessment exercise.

Organisations should learn from:

Incidents Near Misses Audits Control Testing Threat Intelligence Risk Reviews Business Change

Signs of increasing maturity

Consistent methodology

Teams assess similar risks using comparable approaches.

Clear ownership

Important risks have accountable owners.

Business integration

Cybersecurity risk feeds into wider enterprise decisions.

Useful measurement

Risk indicators provide meaningful information.

Continuous monitoring

Significant changes trigger reassessment.

Learning

Lessons from incidents and assessments improve future decisions.

๐Ÿ“ถ Risk Maturity From reactive to integrated

Risk maturity models help organisations evaluate how developed and repeatable their risk-management capability is.

Models differ, but a simplified maturity progression might look like:

1. Ad hoc

Risk decisions are inconsistent and mainly reactive.

2. Repeatable

Some common processes exist but may vary between teams.

3. Defined

Organisation-wide processes and responsibilities are documented.

4. Measured

Risk performance and outcomes are monitored using meaningful data.

5. Optimised

Risk management is integrated into strategic decisions and continuously improved.

Maturity models use different names and numbers of levels. The important concept is progression from inconsistent risk management toward repeatable, measured and continuously improved processes.

11 Risk Frameworks Structured approaches to managing security risk

Organisations can use established frameworks to create consistent approaches to cybersecurity risk.

๐Ÿ‡บ๐Ÿ‡ธ NIST

NIST provides extensive guidance for identifying, assessing, responding to and monitoring cybersecurity risk.

The NIST Risk Management Framework and IR 8286 series connect cybersecurity risk with organisational and enterprise risk management.

๐ŸŒ ISO

ISO/IEC standards provide internationally recognised approaches to information security and risk management, including the ISO/IEC 27000 family.

๐Ÿ›๏ธ COBIT

COBIT provides governance and management guidance connecting enterprise information and technology risk with business objectives.

๐Ÿ—๏ธ SABSA

SABSA provides a business-driven security architecture approach in which security requirements are derived from business needs.

๐Ÿ’ณ PCI

Payment Card Industry standards establish security expectations for environments handling payment-card information.

No universal "best" framework

Framework selection should reflect organisational requirements, industry, objectives, regulatory environment and risk-management needs.

A useful NIST risk-management view

๐Ÿ–ผ๏ธ Frame โ†’ Establish the context for risk
๐Ÿ“Š Assess โ†’ Identify and analyse risk
๐Ÿ›ก๏ธ Respond โ†’ Select an appropriate risk response
๐Ÿ‘๏ธ Monitor โ†’ Track risk and changes over time
๐Ÿข Cybersecurity Risk and Enterprise Risk Cyber risk is business risk

Cybersecurity risks should not remain trapped inside a security department.

Major cybersecurity risks can affect:

Revenue Customers Strategy Operations Compliance Safety Reputation
Example

A ransomware risk affecting a manufacturing plant is not merely an "IT risk".

It may affect production, customer delivery, revenue, safety, contractual obligations and corporate reputation.

Significant cybersecurity risk therefore belongs within wider enterprise-risk discussions.
โš ๏ธ Common mistakes Risk concepts people frequently confuse
"A vulnerability is a risk."

A vulnerability is a weakness. Risk requires consideration of the threat scenario and potential consequences.

"Risk = vulnerability severity."

Technical severity is important, but organisational risk also depends on exposure, likelihood, business context and impact.

"The goal of risk management is zero risk."

Zero risk is rarely achievable. Organisations manage risk in the context of objectives, cost, appetite and tolerance.

"Insurance eliminates cyber risk."

Insurance may transfer some financial consequences but cannot remove every operational, legal or reputational consequence.

"Residual risk means the control failed."

Controls commonly reduce rather than completely eliminate risk. Residual risk is the portion remaining afterward.

"Risk acceptance means doing nothing."

Proper acceptance is an informed, documented and authorised business decision.

"High CVSS means high business risk."

A technically severe vulnerability may present limited organisational risk if the vulnerable component is not exposed or does not support important assets.

"Low CVSS means low business risk."

A lower-severity technical weakness could still create significant risk in a sensitive business context.

"The security team accepts the business risk."

Security provides expertise and assessment. Risk acceptance should be made by an appropriately authorised risk owner.

"Risk assessments are annual documents."

Significant changes in threats, controls, systems or business context may require reassessment before the next scheduled review.

CISSP Exam Perspective

Think like a risk advisor, not only a technician

CISSP questions often present a technical problem but ask for the best risk-management response.

Understand the business context before jumping directly to a technical control.

โšก Identify

Threat Vulnerability Asset Scenario Scope

๐Ÿ“Š Analyse

Likelihood Impact Qualitative Quantitative Residual

๐Ÿ›ก๏ธ Respond

Avoid Mitigate Transfer Accept Controls

๐Ÿ‘ค Governance

Risk Owner Authority Appetite Tolerance Business

๐Ÿ‘๏ธ Monitor

KRI KPI Control Effectiveness Change Review

๐Ÿ“ฃ Communicate

Risk Register Management Board Regulator Reporting
๐Ÿ“ Practice scenarios Apply risk-management thinking

Scenario 1 โ€” Vulnerability discovered

A vulnerability scanner reports a critical vulnerability.

What should happen next?

Understand the affected asset, exposure, relevant threats, existing controls and potential business impact before determining the appropriate risk response.

Scenario 2 โ€” Remove the risky service

Management decides that a risky service provides insufficient business benefit and permanently closes it.

Risk treatment:

Avoidance.

Scenario 3 โ€” Install MFA

The organisation introduces MFA to reduce the likelihood that stolen passwords can be used successfully.

Risk treatment:

Mitigation.

Scenario 4 โ€” Cyber insurance

The organisation purchases an insurance policy covering certain incident-response costs.

Risk treatment concept:

Transfer or sharing of some financial consequences.

Scenario 5 โ€” Low residual risk

Existing controls reduce a risk to a level management considers acceptable.

Risk response:

Formal acceptance of the residual risk may be appropriate.

Scenario 6 โ€” SLE calculation

Asset Value = ยฃ200,000

Exposure Factor = 25%

What is the SLE?

ยฃ200,000 ร— 0.25 = ยฃ50,000.

Scenario 7 โ€” ALE calculation

SLE = ยฃ50,000

ARO = 0.5

What is the ALE?

ยฃ50,000 ร— 0.5 = ยฃ25,000 per year.

Scenario 8 โ€” Control exists

Management believes MFA protects every privileged account, but an assessment discovers that several legacy administrator accounts bypass MFA.

What should be reconsidered?

Control effectiveness and therefore the residual risk.

Scenario 9 โ€” Threat environment changes

A vulnerability previously had no known exploitation. Active attacks are now being widely reported.

What should happen?

Reassess the risk because likelihood has changed.

Scenario 10 โ€” Who accepts?

A penetration tester identifies a serious weakness and decides that the organisation should simply accept it.

What is wrong?

The tester can advise on risk, but acceptance should be made by an appropriately authorised risk owner.

Scenario 11 โ€” Qualitative assessment

A risk is described as "High likelihood and Medium impact."

Analysis type:

Qualitative.

Scenario 12 โ€” Quantitative assessment

A risk is estimated to produce an average annual financial loss of ยฃ75,000.

Analysis type:

Quantitative.

Risk Management thinking flow

๐Ÿ’Ž Asset โ†’ What do we value?
โšก Threat โ†’ What could cause harm?
๐Ÿ•ณ๏ธ Vulnerability โ†’ What weakness exists?
๐Ÿ“Š Analyse โ†’ How likely and how damaging?
๐Ÿ›ก๏ธ Treat โ†’ Avoid, mitigate, transfer or accept?
โš–๏ธ Residual Risk โ†’ What remains?
๐Ÿ‘๏ธ Monitor โ†’ Has anything changed?

Quick memory aid

Threat What could HARM us?
Vulnerability What WEAKNESS exists?
Likelihood How likely is it to HAPPEN?
Impact How BAD would it be?
Risk Should we CARE?
Treatment What will we DO?

Identify. Analyse. Treat. Monitor.

Risk treatment memory aid

Avoid STOP the activity
Mitigate REDUCE the risk
Transfer SHARE some consequence
Accept KEEP the residual risk

Stop. Reduce. Share. Keep.

Quantitative risk memory aid

AV Asset Value
EF Percentage lost in one event
SLE AV ร— EF
ARO Events per year
ALE SLE ร— ARO

SLE = ONE EVENT ยท ALE = ONE YEAR

Key takeaways

Risk management supports informed business decision-making. Its purpose is not simply to produce vulnerability lists or eliminate every possible risk.

A useful risk scenario connects assets, threats, vulnerabilities, events and business consequences.

Risk is commonly considered through likelihood and impact.

Qualitative analysis uses descriptive categories such as Low, Medium and High.

Quantitative analysis uses numerical estimates.

Traditional quantitative CISSP calculations include SLE = AV ร— EF and ALE = SLE ร— ARO.

Inherent risk represents risk before focused management action, while residual risk remains after risk treatment and controls.

Risk can be avoided, mitigated, transferred/shared or accepted.

Cybersecurity insurance can transfer some financial consequences but does not make the underlying operational or security risk disappear.

Controls can serve functions including preventive, detective, corrective, deterrent, recovery and compensating purposes.

Controls should be assessed for implementation and effectiveness rather than assumed to work simply because they exist.

Significant risks should have appropriate risk ownership and should be recorded, monitored and reviewed.

Risk changes as threats, vulnerabilities, systems, controls and business conditions change.

Cybersecurity risk is ultimately business risk. Important cyber risks should therefore connect to wider enterprise-risk management and organisational objectives.

Most importantly: security professionals identify and explain risk so that the right people can make informed decisions about it.

๐Ÿ“š Sources & Further Reading Authoritative references