312-50V9 · Question #479
If the final set of security controls does not eliminate all risk in a system, what could be done next?
The correct answer is C. If the residual risk is low enough, it can be accepted. After applying security controls, any remaining exposure is called residual risk, which can be formally accepted by management if it falls below an acceptable threshold.
Question
If the final set of security controls does not eliminate all risk in a system, what could be done next?
Options
- AContinue to apply controls until there is zero risk.
- BIgnore any remaining risk.
- CIf the residual risk is low enough, it can be accepted.
- DRemove current controls since they are not completely effective.
How the community answered
(51 responses)- A8% (4)
- B18% (9)
- C71% (36)
- D4% (2)
Why each option
After applying security controls, any remaining exposure is called residual risk, which can be formally accepted by management if it falls below an acceptable threshold.
Zero risk is unattainable in any real-world system; attempting to eliminate all risk entirely is neither practical nor cost-effective.
Ignoring risk is not a formal risk treatment strategy and leaves the organization without a documented decision or accountability.
Residual risk is the risk that remains after security controls have been implemented. Risk management frameworks such as NIST SP 800-30 explicitly allow organizations to accept residual risk when its level is deemed tolerable relative to the cost of further mitigation. Formal risk acceptance is a legitimate and documented risk treatment option, distinct from ignoring risk.
Removing existing controls because they are not perfect would increase overall risk rather than reduce it, which is counterproductive.
Concept tested: Residual risk acceptance in risk management
Source: https://csrc.nist.gov/pubs/sp/800/30/r1/final
Topics
Community Discussion
No community discussion yet for this question.