Tyscorpa Study resources Open the Academy

Risk Management

Risk identification, assessment, treatment strategies, BIA, and quantitative vs. qualitative analysis.

SY0-701 Obj. 5.2 Security Program Management 20% of the exam

Risk Terminology

TermDefinitionExample
ThreatAny circumstance or event that could harm an assetRansomware attack, hurricane, disgruntled employee
VulnerabilityA weakness that can be exploited by a threatUnpatched OS, weak password policy, unlocked server room
RiskThe likelihood × impact of a threat exploiting a vulnerabilityRisk of ransomware = high likelihood × high impact = Critical
AssetWhat you're trying to protect (hardware, data, people, reputation)Customer database, production servers, intellectual property
Residual RiskRisk remaining after controls are appliedAfter MFA + patching, remaining ransomware risk is Low
Inherent RiskRisk before any controls are appliedRaw risk of a new web application before security review
Risk AppetiteAmount of risk an organization is willing to acceptA bank has very low risk appetite; a startup may accept more
Risk ToleranceAcceptable deviation from risk appetite for specific scenariosAccept slightly higher risk for a short-term project

Risk Calculation

Risk = Likelihood (Probability) × Impact

Quantitative formulas:

Example:
Asset value = $100,000 (server)
Exposure factor = 0.3 (30% of server lost in a fire)
SLE = $100,000 × 0.3 = $30,000
ARO = 0.1 (fire once every 10 years)
ALE = $30,000 × 0.1 = $3,000/year
→ Installing a sprinkler system costs $500/year → worthwhile!

Qualitative vs. Quantitative Risk Analysis

QualitativeQuantitative
MethodSubjective ratings (High/Medium/Low)Numerical values (ALE, SLE, ARO)
ProsFast; no hard data needed; good for initial triageObjective; enables cost-benefit analysis; defensible to management
ConsSubjective; hard to compare or prioritizeTime-consuming; requires accurate asset valuation and probability data
ToolsRisk matrix (heat map)ALE calculations, Monte Carlo simulation

Risk Treatment Strategies

StrategyDescriptionExample
AcceptAcknowledge the risk and consciously choose not to act. Used when cost of control > cost of risk.Accept the risk of a very rare, low-impact event (within risk appetite)
TransferShift financial impact to a third party.Cyber insurance; outsourcing to a managed security provider
AvoidEliminate the activity or asset that creates the risk.Not launching a risky product feature; discontinuing a vulnerable service
Mitigate / ReduceImplement controls to reduce likelihood or impact.Patching, MFA, encryption, network segmentation

Note: "Ignore" is never an acceptable risk treatment option on the exam!

Business Impact Analysis (BIA)

BIA identifies the organization's critical business functions and quantifies the impact of their disruption.

Supply Chain Risk

Exam Tip: Risk treatment memory aid: TAMA — Transfer, Accept, Mitigate, Avoid. Remember: residual risk always remains after any control. Risk transference (insurance) doesn't eliminate the risk — only its financial impact. BIA outputs inform RTO/RPO which drive DR site decisions.
PreviousSecurity Governance NextThird-Party Risk & Vendor Management

Test yourself on this

Reading is the easy half. The Academy has 1,360 exam-style questions, including performance-based ones, and it keeps pulling from whichever domain you keep getting wrong. Free to create an account.

Open the Academy