Risk Appetite Flashcards
What is risk appetite?
the amount of risk an org is ready to take on to achieve its strategic objectives
What is risk tolerance?
the degree of variance from the org’s risk appetite that the org is willing to tolerate
What is an RAM?
Risk assessment methodology, a unique risk assessment template that can be applied to assess a risk scoped with an entity or an object
What is an RCSA?
Risk and control self-assessment, a process that allows an organization to evaluate all risks and control effectiveness related to a specific entity
Where does a risk assessor assess risks or objects by responding to factors?
Risk assessment instance
What are factors?
The risk assessment questions, each has its own contribution
What are the three assessment types?
Inherent, control, residual
What are the 2 options for expressing risk appetite limits?
Qualitative and quantitative
What are the 3 types of factors?
manual, automated, group