ISC2-CC - Security Principles - Section 1.2

Understand the risk management process, including risk identification, assessment, and the treatment options of avoidance, mitigation, transfer, and acceptance.

Walk through the risk management lifecycle: identify assets and threats, assess the likelihood and impact of each risk, and select a treatment. Distinguish the four risk treatment options - avoid, mitigate (reduce), transfer (e.g. insurance), and accept - and recognise that residual risk remains after controls are applied and must be formally accepted by management.

Risk managementRisk assessmentRisk treatmentResidual riskThreat and vulnerability

Practice question for this objective

Free sampleSecurity Principlesmedium

After a company deploys encryption, access controls and monitoring, some risk to its customer database still remains. In risk management terminology, what is the name for the risk that persists after controls have been applied?

  • AInherent risk, the level of risk present before any controls or treatment are considered.
  • BResidual risk, the risk remaining after risk treatment and controls have been put in place. Correct
  • CTotal risk, the full exposure calculated from every threat facing the asset combined.
  • DTransferred risk, the portion of exposure that has been shifted to a third party by contract.
Residual risk is the exposure that remains after controls and risk treatment have been applied. Controls rarely eliminate risk completely, so the exposure left after treatment is termed residual risk, and the organisation must decide whether that remaining level is acceptable or needs further action.

Why A is wrong: Inherent risk is the starting exposure before controls; the question asks about what is left afterwards, which is a different measure.

Why B is correct: Residual risk is precisely the exposure that remains once mitigations are applied, which management then accepts or treats further.

Why C is wrong: Total risk describes overall exposure without regard to controls, so it does not name the portion that specifically remains after treatment.

Why D is wrong: Transfer is a treatment option, not the general term for leftover risk; controls here reduce risk in place rather than shifting it to another party.

See more ISC2-CC practice questions with worked answers.

More in this domain

Back to all Security Principles objectives, or the ISC2-CC cert hub.

Examworthy is not affiliated with or endorsed by ISC2. Original, blueprint-aligned practice material only.