CCSK · Question #222
Which of the following defines the amount of risk that the leadership and stakeholders of an organization are willing to accept?
The correct answer is B. Risk Tolerance. Risk tolerance defines the degree of risk that an organization's leadership and stakeholders are willing to accept in pursuit of their objectives.
Question
Which of the following defines the amount of risk that the leadership and stakeholders of an organization are willing to accept?
Options
- ARisk Acceptance
- BRisk Tolerance
- CResidual Risk
- DRisk Target
How the community answered
(42 responses)- A17% (7)
- B71% (30)
- C5% (2)
- D7% (3)
Why each option
Risk tolerance defines the degree of risk that an organization's leadership and stakeholders are willing to accept in pursuit of their objectives.
Risk acceptance is a risk response strategy where an organization consciously decides to accept a specific identified risk rather than mitigate, transfer, or avoid it - it is an action, not a defined organizational threshold.
Risk tolerance is the formally defined threshold of risk that leadership and stakeholders are prepared to accept, reflecting the organization's capacity and willingness to absorb uncertainty. It sets the acceptable boundaries within which risk management operates and is used by decision-makers to guide strategy and control investments. Both NIST SP 800-30 and ISO 31000 define risk tolerance as the level of risk deemed acceptable by organizational leadership.
Residual risk is the risk that remains after controls and countermeasures have already been applied to a threat or vulnerability.
Risk target is not a standard term in widely recognized risk management frameworks and does not specifically represent the willingness to accept risk as defined by leadership.
Concept tested: Risk tolerance definition in organizational risk management
Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.