CGRC · Question #178
An organization's decision on acceptable degrees of residual risks should be based on; choose one. Response:
The correct answer is C. Organizational risk tolerance. An organization's decision regarding acceptable degrees of residual risk should be consistently based on its established organizational risk tolerance, which defines the maximum acceptable risk level.
Question
An organization's decision on acceptable degrees of residual risks should be based on; choose one. Response:
Options
- ASystem-level risk appetite
- BOrganizational risk picture
- COrganizational risk tolerance
- DTier 3 risk tolerance
How the community answered
(53 responses)- A4% (2)
- B2% (1)
- C92% (49)
- D2% (1)
Why each option
An organization's decision regarding acceptable degrees of residual risk should be consistently based on its established organizational risk tolerance, which defines the maximum acceptable risk level.
System-level risk appetite is too granular; organizational risk tolerance provides the enterprise-wide context for acceptable risk across all systems.
Organizational risk picture is a current assessment of risks, not the predefined benchmark for acceptable risk levels.
Organizational risk tolerance is the overarching level of risk an organization is willing to accept after security controls have been implemented. Decisions about whether the remaining (residual) risks are acceptable must align with this predefined tolerance to ensure consistency and adherence to the organization's risk management strategy.
Tier 3 risk tolerance refers to the enterprise-wide perspective within NIST's three-tiered risk management approach, which is a specific framework, but 'Organizational risk tolerance' is the more general and widely applicable term for setting acceptable residual risk.
Concept tested: Organizational risk tolerance and residual risk
Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-39.pdf
Topics
Community Discussion
No community discussion yet for this question.