ISC2 Certified in Cybersecurity (CC)Security PrinciplesMedium

A multinational corporation is considering expanding its operations into a new region. Before making a final decision, the board of directors wants to understand the maximum amount of residual risk they are willing to accept after implementing all planned security controls. What specific concept are they trying to determine?

  1. ARisk Likelihood
  2. BRisk Impact
  3. CRisk Tolerance
  4. DRisk Treatment
Show answer & explanation

Correct answer: C. Risk Tolerance

Risk tolerance is the acceptable deviation from achieving objectives related to risk. It defines the maximum amount of risk an organization is willing to accept after risk treatment has been applied.

Why the other options are wrong

  • A. Risk Likelihood is the probability of a risk occurring.
  • B. Risk Impact is the severity of harm caused by a risk event.
  • D. Risk Treatment refers to the actions taken to modify risk (e.g., mitigate, accept, transfer, avoid).

Risk Tolerance

The acceptable deviation from achieving objectives related to risk. It is the specific maximum level of risk an organization is willing to accept after risk treatment.

  • Often expressed qualitatively or quantitatively.
  • Determined by executive management.
  • Differs from risk appetite, which is the overall desired risk level.

Memory trick: Appetite wants, tolerance allows, treatment acts.

More Security Principles questions