An organisation cannot protect everything equally, and pretending otherwise protects the wrong things. A risk assessment makes the trade-offs explicit. It lists the assets that matter, the threats to each, and the weaknesses those threats could use; it estimates, for each combination, how likely it is and how bad it would be; and it produces a ranked list from which someone with authority decides what to do. The estimates are rough, the ranking is disputable, and the exercise is still worth more than any alternative, because the alternative is spending the budget on whatever was in the news.
| Response | Meaning | When it fits |
|---|---|---|
| Mitigate | Add a control that lowers likelihood or impact | The common case: the fix costs less than the expected harm |
| Accept | Decide to live with it, and record who decided and until when | The harm is small, or the fix costs more than it saves |
| Transfer | Insure it, or contract it to a party who bears it | Rare, large losses that a premium can cover; outsourcing that moves the exposure |
| Avoid | Stop doing the thing that creates the risk | The activity is not worth its exposure, which is asked less often than it should be |
Likelihood and impact are estimated, not measured, and the honest methods say so. Qualitative scales, low to high, are quick and consistent enough to rank; quantitative methods put currency figures on expected loss and are harder, more contestable and far more persuasive to the people who hold budgets. Either way the point is the ranking and the decision, and the decision has to be owned. A risk that is accepted by nobody in particular has not been accepted; it has been ignored with paperwork. The governance-tier security credentials test this as their central skill: put the decision where the accountability sits, in language the business owner can accept or refuse.
Registers decay. Threats change, systems are replaced, the person who accepted a risk leaves, and the register keeps saying what it said the year it was written. A useful register has a review date on every line, an owner who still works there, and a link from each mitigation to something you can check happened. The audit certifications test the ability to evidence exactly that: not that a risk was assessed, but that the control the assessment demanded operated and someone can prove it.
