Risk Reporting Flashcards
Capacity for loss
Objective measure of how much loss the organization can withstand and remain solvent
Tolerance for Loss
Subjective measure of how much loss an organization is willing to withstand.
Tolerance can vary among stakeholders/scenarios.
Fragile condition
Facing many threat events, but none are becoming loss events because of a single control.
What happens if it fails?
Threat events become loss events
Unstable condition
High vulnerability but no threat events. (No threat events at the moment and no controls)
What if threat community starts attacking?
Threat events become loss events.
H/M/L Labels
High Medium Low
Translation table
Always required when using H/M/L labels to avoid subjective interpretations
Risk Rating: SV
Severe
Risk rating: H
High
Risk rating: Sg
Significant
Risk rating: M
Moderate
Risk rating: L
Low
Risk rating: VL
Very low
How to remediate fragile condition…
Add additional layers of control