Risk treatment: The process of selecting and implementing measures to modify risk. This can include avoiding the risk, optimizing the risk through mitigation strategies, sharing the risk with other parties, or retaining the risk by informed decision. The aim is to reduce the level of risk to an acceptable level as per the organization’s risk appetite.
Categories: CC D1: Security Principles | CCSP D6: Legal - Risk and Compliance | CISM D2: Information security risk management | CISSP D1: Security and Risk Management | Security+ D5: Security Program Management and Oversight | SSCP D3: Risk Identification Monitoring and Analysis
Related Articles: