From the course: ISACA Certified Information Security Manager (CISM) Cert Prep

Risk acceptance

- [Instructor] In our previous section, we talked about our risk action plan. So we've looked at the value of the risk, we've determined what our response is and how we're going to move forward in that risk action plan. But let's focus a little bit on what those risk options are going to be. So when we talk about responding to a risk, we've got four basic choices. So we can accept the risk, we can mitigate it, avoid it, or transfer it. Now the first risk response that we're going to talk about is risk acceptance, all right? So when we talk about accepting a risk, our ultimate goal is to bring down what risk there is to a degree that's acceptable. So when we talk about accepting risk, that's the point where we no longer mitigate. Now out of the box, some risks may be an acceptable level because, remember, there's a certain amount of just inherent risk with everything. And many risks inherently have acceptable levels, right? I mean, there's a risk that comes with crossing the street. So you mitigate, you know, you do what you can, you look both ways, you cross at a crosswalk, but then above that and beyond, you really accept what risk there is. So it either just has inherent acceptable risk, or we mitigate to the role or to the degree that's acceptable, all right? Now, with acceptable risk, we no longer mitigate, once we reach that acceptable level, because, again, you kind of get to that point of diminishing returns. So when I mitigate risk to the degree that's acceptable, I don't keep throwing money at the problem, right? That's the whole reason that management has set up an acceptable level of risk. Now, the other thing that's really important about this is that it is a conscious decision. And this says made by senior management, we're going to really kind of say the risk owner, which could absolutely be senior management, but I think risk owners probably a better term here, okay? So it's a conscious decision to look at the existence of the risk. So it's not ignoring a risk, it's not sticking your fingers in your ear and going, "La, la, la, la, la, it doesn't exist," right? So we look at the risk, we examine it and we analyze it. And when we look at the loss potential and we compare that to the value or to the cost of the countermeasure, and we determine it costs more to mitigate the risk than the risk itself, well, that's a good indication that it's time to accept the risk. Sometimes, you have to accept a risk 'cause there's nothing else you can do about it, right? If my project is two weeks late, I have to accept the fact that it's two weeks late, I have to accept the risk that we are going to come in beyond schedule. Now that acceptance has to be made with a clear understanding of probability and impact of the risk, all right? Impact is huge when we talk about risk acceptance because we're no longer mitigating. So, again, has to fall within the acceptable level, must be a conscious decision, again, risk ignorance is not the same, that's the same as risk rejection. So I think a good question might be, okay, if you do nothing, when you accept a risk and you also do nothing when you reject a risk, well, what's the difference? Tomato, tomato, not at all. Risk acceptance uses due diligence, risk rejection does not. So when it comes down to ideas like culpable negligence, you're much more likely to be found liable if you've rejected a risk. But with risk acceptance, I have a paper trail and I can show and justify, you know, here was our potential for loss, here's how much money it would've cost us to mitigate that risk, and even with that, maybe the control isn't all that effective, whatever it is, and I can show that it was a legitimate business decision. And again, when we accept a risk, ideally that risk is within the tolerance level. So look for a phrase 1 or some sort of iteration of risk acceptance. 1 Residual risk is the point at which you accept risks, okay? 1 You mitigate risks until the residual risk 1 falls within acceptable levels. 1 Now, like I said, 1 there are lots of reasons that we may accept a risk. 1 Generally, it's when the cost of the countermeasure 1 is greater than the potential for loss. 1 But like I said, 1 there are some risks that 1 you just don't have any control over 1 that you just have to accept, okay? 1 Now, also, risks that are generally very improbable, 1 even if they're high impact 1 or low probability, low impact, 1 you know, when we talked about our risk assessment, 1 we talked about the probability and impact matrix. 1 So when we have certain risks that fall 1 within that first risk band, 1 where they are, you know, 1 of a low probability and a low impact, 1 that generally is one of those things 1 that pushes us towards risk acceptance. 1 Now, that risk acceptance level should be known, 1 so it's not so much of an individual decision. 1 So we go back to our risk register, 1 which we created earlier where we did the qualitative risk 1 and the qualitative assessment 1 helped us prioritize risk based on probability and impact, 1 we used tools like the risk bands 1 and then those in a specific area 1 as dictated by the, you know, organizational policy 1 or the decisions made of the project, whatever it is, 1 those that are in the acceptable level, we move on, 1 we spend our money on those risks that are not acceptable. 1 Now, this second to last bullet point, 1 risk acceptance is often based on 1 poorly calculated risk levels. 1 You know what? 1 The type of risk I'm talking on this slide, 1 talking about on this slide, that's true. 1 So, you know, when we look and we determine, 1 "Hey, I'm going to meet my project date, 1 I'm not going to meet my project end date, 1 as particularly stated," 1 yeah, you know, at that point in time, 1 you have no choice but to accept the risk, 1 and what's happened? 1 What's made me late? 1 Risk has made me late on my project, right? 1 Perhaps unmitigated risks, risk responses that failed. 1 So I'd rather this be risk acceptance 1 can be based on poorly calculated risk levels. 1 Risk acceptance is a perfectly valid response, 1 absolutely, it is the correct response in many situations. 1 However, sometimes, 1 those times when you're left with just no choice 1 but to accept a risk, 1 a lot of times we'd make mistakes 1 in evaluating those risks, okay? 1 Now we accept a risk, 1 the risk falls within acceptable level. 1 We know that we're not done, right? 1 You never just, you know, brush your hands together 1 and say, "Whew, we have dealt with risk, 1 now I can go on vacation for a month." 1 Never, risk never takes a holiday, right? 1 So even though we've chosen to accept a risk today, 1 doesn't mean, in five years, that's still a good response. 1 As a matter of fact, 1 it doesn't mean that next year 1 that's still a good risk response. 1 So because the threat landscape is always changing, 1 because there are various things 1 that impact our risk profile, 1 we always want to remember whatever our decision is, 1 regular reviews are essential. 1 C risk specifies a regular review as at least once per year 1 or in the event of a major change, okay? 1 So we have a particular risk that we've accepted, 1 next year or in a year from then, 1 and as part of our regular annual risk review, 1 we go back and we look at our controls 1 to determine, are they still sufficient?

Contents