CompTIA Security+ (SY0-701)Security Program Management and OversightMedium
A financial firm's board sets a specific limit stating that no more than 2 hours of downtime per quarter is acceptable for critical trading systems. This specific, measurable limit is best described as the organization's risk:
- AAvoidance
- BAppetite
- CRegister
- DTolerance
Show answer & explanationAnswer & explanation
Correct answer: D. Tolerance
Risk tolerance refers to the specific, measurable acceptable deviation from an objective, such as a precise downtime limit. Risk appetite is the broader, general willingness to accept risk in pursuit of objectives.
Why the other options are wrong
- A. Risk avoidance is a treatment strategy, not a measurement of acceptable limits.
- B. Appetite is a general statement of willingness to accept risk, not a specific metric.
- C. A risk register is a document listing identified risks, not a limit.
Risk Appetite vs Risk Tolerance
Risk appetite is the general amount of risk an organization is willing to accept, while risk tolerance is the specific, quantifiable acceptable variation from that appetite.
- Appetite = broad, qualitative statement
- Tolerance = specific, measurable threshold
- Both guide risk-based decision making
Memory trick: Appetite is the Mood, Tolerance is the Number