TechKnowSurge
CompTIA Security+ 5.2 ISC2 CISSP 1.9 CompTIA SecurityX 1.2 NIST CSF GV.RM-04 NIST CSF ID.RA-07 NIST 800-53 PM-9
VideoSecurityFree

Risk Management Strategies

Risk management strategies help organizations bring unacceptable risks within policy thresholds through avoidance, reduction, transference, or acceptance. Understanding the distinction between risk exceptions and exemptions is essential for proper governance and compliance.

Complete this video to capture a CTF flag worth 1 point.

About this video

Every organization operates within a defined risk appetite, and when a potential risk exceeds that threshold, specific management strategies exist to bring it to an acceptable level. The four primary approaches are avoidance, reduction, transference, and acceptance. Avoidance means eliminating the activity that generates the risk altogether. Reduction involves limiting the impact should the risk be realized, such as deleting sensitive data immediately after processing rather than storing it long-term. Transference shifts responsibility to another party, a common example being the use of a third-party payment processor so that credit card data never resides on an organization's own systems. Acceptance means proceeding despite the elevated risk, typically when the business value outweighs the exposure. Acceptance itself comes in two distinct forms: exceptions and exemptions, and the difference matters for governance. An exception is a case-by-case approval granted by senior leadership that allows an activity to proceed outside the boundaries of an existing policy. An exemption, by contrast, results in a formal change to the policy itself, adding language that excludes certain mission-critical activities from the policy's requirements. For example, if accepting credit card payments is essential to business operations, leadership may update the risk policy to exempt revenue-generating payment activities from the standard risk ceiling, provided alternatives have been genuinely considered and ruled out. Recognizing which mechanism applies in a given situation ensures that risk decisions are properly documented, authorized, and defensible under audit.

What you'll learn

What's covered

Risk Mitigation Strategies

Aligned to

CompTIA Security+
5.2 Explain elements of the risk management process.
ISC2 CISSP
1.9 Understand and apply risk management concepts
CompTIA SecurityX
1.2 Given a scenario, implement the appropriate risk management strategies, policies, and controls.
NIST CSF
GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated.
ID.RA-07 Changes and exceptions are managed, assessed for risk impact, recorded, and tracked.
NIST 800-53
PM-9 Risk Management Strategy

Key terms

Risk
The potential for loss or harm resulting from a threat exploiting a vulnerability.
Risk Management
The ongoing process of identifying, assessing, and mitigating risks to an acceptable level.
Risk Avoidance
A risk response strategy that eliminates exposure to a risk by choosing not to engage in the activity that creates it.
Risk Reduction
A risk response strategy that takes steps to decrease the probability or impact of a risk.
Risk Transference
A risk response strategy that shifts the financial or operational burden of a risk to a third party, such as through insurance.
Risk Acceptance
A risk response strategy that acknowledges a risk and proceeds without additional mitigation because the benefits outweigh the potential harm.
Risk Exception
A formal, one-time approval granted by authorized leadership allowing an entity to deviate from an existing risk policy under special circumstances.
Risk Exemption
A permanent or standing modification to a risk policy that excludes specific scenarios from the policy's requirements, typically when an action is mission-critical.

Topics

Risk Management Risk Avoidance Risk Transference Risk Acceptance Risk Reduction Risk Exceptions Governance And Compliance

Transcript

There are going to be certain risks that we're not going to want to take on, certain risks that might fall outside of our comfort zone from a risk perspective, that extend beyond our risk appetite, or there could be other reasons as well. There are some management strategies to deal with those types of risks, to get them below that threshold or get them to an acceptable point.

Four Strategies

One thing we could do with risk is avoid it altogether. There are certain scenarios where we could not do something, or do something, to just avoid whatever risk that we had.

Or we could reduce the impact. If that risk is actualized, if it takes place, then the risk has a lower impact, and so we can reduce that impact.

Or we could transfer the risk — maybe transfer it to some other entity, like take out insurance on some sort of risk.

Or we can accept the risk and just realize that it's a risk with whatever we're doing.

A Scenario: Taking Credit Cards

To illustrate these, let's come up with a scenario. Let's say our policy says that no risk can be greater than $100,000. So now here is our risk tolerance right here, or our risk threshold, or our risk appetite, whichever term you want to use for it.

Let's say we're rolling out a new product that we're going to charge end users for through an e-commerce site. We're going to be accepting credit cards. Now, during this accepting of credit cards, what's going to happen is we're taking on risk — for instance, that credit card information could get stolen by some other entity and we could be liable for it. Because of that, we've determined that this risk is at $250,000, which is significantly more than the threshold we have in our policy. Somehow we need to reduce the risk that credit cards bring on.

Number one, we could avoid it altogether. Maybe we just don't do any credit card processing, maybe we're going to give the product away for free. It might not be a great solution, but in this case we would be avoiding that risk.

The next thing we could do is reduce the impact. Maybe we take the credit card information, we process it, but then we delete it right away. That might work in a lot of cases, where we don't really need to hold on to that credit card information. But maybe we want to charge them on a monthly basis — now we're probably going to have to hold on to that card in order to process that information on a monthly basis, so that might not be a great solution either.

We could transfer it. There are ways that we can use third-party processors: we send them to the third-party processor to process the credit card information, and then on a monthly basis we can just charge that card, and that card never gets stored on our systems. So what we've done is we've transferred that to whatever service that we're using.

The other one was that we could just accept it — that it is much above and beyond what we have as far as our policy is concerned, but it's worth the risk, because we're going to be getting a lot of money through the extra services that we're going to be selling.

Exceptions and Exemptions

When it comes to acceptance, we have two different types of acceptance. There's an exemption, or there's an exception.

The terms exception and exemption can be a little confusing, and rightfully so, because the result is the same. In this case we have a $250,000 risk, but we're not going to follow the $100,000 limit that's been imposed upon us. The result is the same, but it is because of two different circumstances.

If you have an exception, you're receiving a special circumstance where you are being excluded from the policy, from the rule. In this case you've gone to maybe the CEO, or maybe the board of directors, or possibly all of the upper management, and you've said this is the circumstance, and they've given you permission to have an exception to the rule and said go ahead and proceed — we want to be able to make this money and we have to do this.

The other scenario is that the rule doesn't apply. Maybe we go in there and say, this could come up again, so what we're going to do is actually change the rule. We're going to add to it, and say that these are the exemptions from it, that it doesn't apply in these scenarios.

So in our circumstances, we already mentioned that exemption just means that you're getting approval to proceed with this credit card. But with the exemption we have this added to the policy: that unless a particular risk can't be avoided — so what they're doing is they're asking you to avoid the risk first — and it's associated with an action that is mission critical. Well, taking credit card information is mission critical, because we want to make money and the business needs to be profitable. So it is mission critical, and therefore what has happened is we've created an exemption, that this rule doesn't exactly apply in this scenario because it's mission critical.

So those are various strategies that we can take.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →