312-50V11 · Question #588
If the final set of security controls does not eliminate all risk in a system, what could be done next?
The correct answer is C. If the residual risk is low enough, it can be accepted.. When security controls cannot eliminate all risk, the remaining residual risk may be formally accepted if it falls within an organization's acceptable risk tolerance.
Question
If the final set of security controls does not eliminate all risk in a system, what could be done next?
Options
- AContinue to apply controls until there is zero risk.
- BIgnore any remaining risk.
- CIf the residual risk is low enough, it can be accepted.
- DRemove current controls since they are not completely effective.
How the community answered
(22 responses)- A9% (2)
- B5% (1)
- C82% (18)
- D5% (1)
Why each option
When security controls cannot eliminate all risk, the remaining residual risk may be formally accepted if it falls within an organization's acceptable risk tolerance.
Absolute zero risk is not a realistic or achievable goal in any real-world system, and indefinitely applying controls is not a practical risk management strategy.
Ignoring remaining risk is irresponsible and violates sound risk management practice, as unacknowledged risk cannot be monitored or managed.
Residual risk is the risk that remains after security controls have been applied. Risk management frameworks such as NIST RMF recognize that zero risk is generally unattainable, so organizations formally evaluate residual risk against their risk tolerance. If the remaining risk is low enough to fall within acceptable thresholds, it can be documented and accepted by the authorizing official.
Removing controls that partially reduce risk would increase overall exposure and is contrary to the goal of minimizing risk to the greatest feasible extent.
Concept tested: Residual risk acceptance in risk management
Source: https://csrc.nist.gov/glossary/term/residual_risk
Topics
Community Discussion
No community discussion yet for this question.