Terminology Index
1801 terms
Showing 1345-1376 of 1801 terms
Risk Appetite
The amount and type of risk an organization is willing to tolerate.
Risk Appetite Cascading
Translating a high-level risk appetite from the board or executive level down into concrete tolerances and thresholds throughout the organization, so it actually drives day-to-day decisions.
Risk Assessment
The structured analysis that identifies risks, evaluates their likelihood and impact, and produces input for treatment decisions. Risk assessment is foundational across security governance, analyst work, and GRC.
Risk Assessment Methodology
The chosen approach to conducting risk assessments, scope, criteria, scoring scales, evidence requirements, that makes assessments consistent and defensible across the organization.
Risk Assessment Scope
Defining what an assessment covers, which systems, processes, threats, and time horizon, so its findings are bounded, comparable, and meaningful rather than vague.
Risk Avoidance
A risk-treatment option that eliminates a risk by not doing the activity that produces it, such as withdrawing from a market or shutting down a high-risk system. One of four foundational treatment options.
Risk Committee Operations
How a risk committee actually runs, its membership, cadence, agendas, decisions, and reporting, that determines whether enterprise risk management is a real operating function or just a body that exists on paper.
Risk Communication
Communicating risk findings and decisions to stakeholders so they understand and can act, framed from the security-analyst perspective of conveying technical risk to non-technical audiences clearly.
Risk Communication Throughout
Communicating risk continuously across the risk lifecycle, not only at assessment, so stakeholders stay aligned on status, decisions, and changes rather than learning about risk only at headline moments.
Risk Context
Establishing the context in which risk is assessed, the organization's objectives, environment, stakeholders, and constraints, so risk analysis is grounded in what actually matters to the organization.
Risk Culture
The shared attitudes, values, and habits around risk in an organization, whether people raise concerns, accept appropriate risks, and behave consistently with stated appetite, that shape outcomes as much as formal controls.
Risk Dashboards
Visual summaries of the risk picture, top risks, trends, treatment progress, that give leadership and risk owners an at-a-glance view to drive decisions and accountability.
Risk Definition
The shared meaning of 'risk' an organization adopts (often impact times likelihood, or chance of consequence), grounding the GRC program in a consistent concept so people are talking about the same thing.
Risk Identification
The step of finding and naming the risks an organization faces, through workshops, scans, threat modeling, and other sources, so they can then be analyzed and treated rather than missed entirely.
Risk Lifecycle
The full sequence each risk moves through, identification, analysis, evaluation, treatment, monitoring, communication, that frames risk management as a continuing process rather than a one-time activity.
Risk Management
The discipline of identifying, analyzing, treating, and monitoring risks to support an organization's objectives, one of the foundational practices of security governance and overall enterprise governance.
Risk Maturity Models
Models that describe maturity levels of a risk-management capability, from ad hoc to optimized, used to assess where an organization stands and plan investment to grow the function over time.
Risk Mitigation
Treating a risk by reducing its likelihood or impact through controls, hardening, processes, or other measures. The most common risk-treatment option in cybersecurity governance.
Risk Monitoring
Continuously tracking risks over time, changes in likelihood and impact, treatment progress, new risks emerging, so the picture stays current rather than frozen at the moment of last assessment.
Risk Program Structure
How the risk-management function is organized, ownership, roles, committees, reporting lines, frameworks, that determines whether risk management operates as a coherent program or a collection of activities.
Risk Register
A record of identified risks, owners, ratings, decisions, and follow-up actions.
Risk Reporting Audiences
The different audiences that consume risk reports, board, executives, risk owners, operations, each needing different content, granularity, and framing for the reporting to be useful.
Risk Statement Construction
Writing clear risk statements that specify the threat, the asset, the impact, and the conditions, so each risk is understandable and actionable rather than vague.
Risk Transfer
Shifting some financial or operational impact of risk to another party, such as through insurance or contracts.
Risk Treatment
Deciding what to do about each identified risk, mitigate, transfer, accept, or avoid, the formal step that turns analysis into action and ties risk to controls and decisions.
Risk Workshops
Facilitated sessions with stakeholders to identify, analyze, or rate risks together, useful for gathering diverse perspectives and producing shared understanding alongside structured outputs.
Risk-Based Audit Planning
Planning audits to focus on the highest-risk areas first, rather than auditing everything equally, so limited audit capacity goes where it most affects outcomes.
Risk-Based Authentication
Authentication that varies its rigor based on risk signals, location, device, behavior, requiring more (or less) when the context suggests higher risk, common in modern IAM and customer-identity systems.
Risk-Based Prioritization
Prioritizing hardening work by the real risk each item carries, exploitability, exposure, impact, rather than treating all findings as equal, so limited time targets the items that matter most.
Risk-Based Tuning
Tuning detections by the risk they address, focusing engineering time on rules covering the most relevant threats and tolerating noise where the underlying threat is critical enough to justify it.
Risk-Based Vulnerability Prioritization
Prioritizing vulnerability remediation by the real risk each one creates, exploitability, exposure, asset value, rather than treating all vulnerabilities by raw severity score.
Role Engineering Value
The benefits of designing roles deliberately, simpler administration, cleaner audits, stronger least privilege, that justify investing in role engineering rather than letting access grow ad hoc.