Types Of Risk Respones Flashcards
Accept the risk
If avoiding, mitigating, or transferring the risk would cost more than expected losses of the realized threat
Mitigate
Also called risk reduction or risk modification
Reduces the likelihood of a threat being realized or lessening the impact that the realized threat would have on the organization.
Example: moving from a single factor to multifactor authentication
Transfer
Also known as risk assignment
Involves shifting the responsibility and potential loss associated with a risk onto a 3rd party.
Example: Insurance
Avoid
Involves eliminating an identity risk by stopping or removing the activity or technology that causes the risk.
Example: policy than ban the use of removable media or personal cloud storage services
Rejection
You know the risk is there but you are ignoring it. Never acceptable