Cyberstudy
PDF p.398 In progress

Risk Management Strategies

Open PDF at p.398 17 flashcards

Summary

PDF p.398

Risk management strategies involve proactive and systematic approaches to identify, assess, prioritize, and mitigate risks to minimize their negative impacts. Key strategies include risk mitigation, avoidance, transference, and acceptance.

In plain words

Supplementary — not from your PDF

There are four core responses to risk. Mitigation (reduction) uses controls to lower exposure. Avoidance stops the risky activity entirely (rarely practical). Transference shifts risk to a third party, such as cyber insurance (though reputation and some legal liability stay with you). Acceptance takes no action because the risk is tolerable. Residual risk is what remains after these measures; risk appetite is how much residual risk you're willing to tolerate.

Detailed explanation

PDF p.398
  • Risk Mitigation (or Remediation)
    • Definition: The process of reducing exposure to or the effects of risk factors.
    • Risk Deterrence (or Reduction): Countermeasures that reduce exposure to threats or vulnerabilities.
    • Examples
      • Policies controlling flammable materials to reduce fire risk.
      • Alarms and sprinklers to contain fire incidents.
      • Off-site data backup for server destruction scenarios.
  • Avoidance
    • Definition: Stopping the activity that causes risk.
    • Example: Discontinuing the sale of a vulnerable application due to security issues and legal threats.
    • Usage: Rarely a credible option.
  • Risk Transference
    • Definition: Assigning risk to a third party, such as an insurance company.
    • Cybersecurity Insurance: Protects against fines and liabilities from data breaches and attacks.
    • Limitations: Reputation risks and some legal liabilities may remain with the original company.
  • Risk Acceptance
    • Definition: No countermeasures are implemented because the risk level is deemed acceptable.
    • Risk Exception: Recognizes unmitigated risks due to financial, technical, or operational constraints, seeking alternate controls.
    • Risk Exemption: Allows risk to remain without mitigation due to strategic decisions, often when mitigation costs outweigh potential harm.
  • Residual Risk and Risk Appetite
    • Residual Risk: The remaining risk after mitigation, transference, or acceptance measures.
    • Risk Appetite: The level of residual risk that is tolerable, assessed strategically and constrained by regulation and compliance.

Important terms

taken from the text above
Risk Mitigation (or Remediation)
The process of reducing exposure to or the effects of risk factors.
Risk Deterrence (or Reduction)
Countermeasures that reduce exposure to threats or vulnerabilities.
Avoidance
Stopping the activity that causes risk.
Risk Transference
Assigning risk to a third party, such as an insurance company.
Cybersecurity Insurance
Protects against fines and liabilities from data breaches and attacks.
Risk Acceptance
No countermeasures are implemented because the risk level is deemed acceptable.
Risk Exception
Recognizes unmitigated risks due to financial, technical, or operational constraints, seeking alternate controls.
Risk Exemption
Allows risk to remain without mitigation due to strategic decisions, often when mitigation costs outweigh potential harm.
Residual Risk
The remaining risk after mitigation, transference, or acceptance measures.
Risk Appetite
The level of residual risk that is tolerable, assessed strategically and constrained by regulation and compliance.

Examples & real-world scenarios

Supplementary — not from your PDF
  • Mitigation: adding sprinklers to reduce fire damage.
  • Transference: buying cybersecurity insurance.
  • Acceptance: documenting a low risk with a review date.

Scenario

A company can't fully fix a legacy system's risk. It buys insurance (transference) for the financial impact but knows reputation damage would still be its own problem.

Common mistakes

Supplementary — not from your PDF
  • Thinking insurance transfers all risk. Reputation and some liability remain.
  • Confusing avoidance (stop the activity) with mitigation (reduce the risk).

Practical skills

Supplementary — not from your PDF
  • Match a response to a risk scenario.

What I should remember

Key Points PDF p.398
  • Risk Mitigation
    • Reduce Exposure: Through policies, alarms, sprinklers, and backups.
    • Risk Deterrence: Countermeasures to reduce likelihood or impact.
  • Avoidance
    • Stop Risky Activities: Discontinue problematic applications.
    • Rare Option: Not commonly feasible.
  • Risk Transference
    • Assign to Third Party: Use of insurance.
    • Limitations: Reputation and some legal risks remain.
  • Risk Acceptance
    • Acceptable Risk Levels: No countermeasures needed.
    • Exceptions and Exemptions: Recognize and document unmitigated risks.
  • Residual Risk and Risk Appetite
    • Post-Mitigation Risk: Residual risk assessment.
    • Strategic Tolerance: Risk appetite for overall risk management.