Terminology Index
2953 terms
Risk Lifecycle
The full sequence each risk moves through, identification, analysis, evaluation, treatment, monitoring, communication, that frames risk management as a continuing process rather than a one-time activity.
Risk Management
The discipline of identifying, analyzing, treating, and monitoring risks to support an organization's objectives, one of the foundational practices of security governance and overall enterprise governance.
Risk Maturity Models
Models that describe maturity levels of a risk-management capability, from ad hoc to optimized, used to assess where an organization stands and plan investment to grow the function over time.
Risk Mitigation
Treating a risk by reducing its likelihood or impact through controls, hardening, processes, or other measures. The most common risk-treatment option in cybersecurity governance.
Risk Monitoring
Continuously tracking risks over time, changes in likelihood and impact, treatment progress, new risks emerging, so the picture stays current rather than frozen at the moment of last assessment.
Risk Ownership and Escalation
Risk ownership and escalation assign a scenario to an accountable leader who can fund treatment or accept exposure within delegated limits and route excess risk to higher authority.
Risk Program Structure
How the risk-management function is organized, ownership, roles, committees, reporting lines, frameworks, that determines whether risk management operates as a coherent program or a collection of activities.
Risk Rating Rationale
Risk rating rationale explains how an approved method, evidence, assumptions, time horizon, control state, uncertainty, and risk appetite produced a risk level.
Risk Register
A record of identified risks, owners, ratings, decisions, and follow-up actions.
Risk Register Integrity
Risk register integrity preserves stable scenarios, scope, ownership, evidence, methods, controls, treatment, authority, targets, assumptions, review triggers, status, and decision history.
Risk Reporting Audiences
The different audiences that consume risk reports, board, executives, risk owners, operations, each needing different content, granularity, and framing for the reporting to be useful.
Risk Scenario Development
Risk scenario development describes a threat or hazardous event, the conditions that enable it, the affected asset or process, and the business consequence within a stated horizon.
Risk Statement Construction
Writing clear risk statements that specify the threat, the asset, the impact, and the conditions, so each risk is understandable and actionable rather than vague.
Risk Transfer
Shifting some financial or operational impact of risk to another party, such as through insurance or contracts.
Risk Treatment
Deciding what to do about each identified risk, mitigate, transfer, accept, or avoid, the formal step that turns analysis into action and ties risk to controls and decisions.
Risk Treatment Decision
A risk treatment decision authorizes avoidance, reduction, transfer or sharing, acceptance, or a combination with defined owner, rationale, conditions, monitoring, evidence, and review.
Risk Workshops
Facilitated sessions with stakeholders to identify, analyze, or rate risks together, useful for gathering diverse perspectives and producing shared understanding alongside structured outputs.
Risk-Adjusted ROI Calculation
A risk-adjusted ROI calculation compares an option's modeled change in loss exposure with its full lifecycle cost under an explicit financial definition and horizon.
Risk-Based Audit Planning
Planning audits to focus on the highest-risk areas first, rather than auditing everything equally, so limited audit capacity goes where it most affects outcomes.
Risk-Based Authentication
Authentication that varies its rigor based on risk signals, location, device, behavior, requiring more (or less) when the context suggests higher risk, common in modern IAM and customer-identity systems.
Risk-Based Authentication Limits
Risk-based authentication limits are the uncertainty, bias, evasion, data-quality, and interpretation problems in device, location, network, reputation, behavior, velocity, and model signals.
Risk-Based Pipeline Gates
Risk-based pipeline gates allow, block, or route a software change using finding confidence, asset context, exposure, impact, and an approved decision policy.
Risk-Based Prioritization
Prioritizing hardening work by the real risk each item carries, exploitability, exposure, impact, rather than treating all findings as equal, so limited time targets the items that matter most.
Risk-Based Remediation Priority
Risk-based remediation priority is a traceable decision that combines validated affectedness, severity, exploitation evidence and likelihood, exposure, consequence, controls, feasibility, and uncertainty.
Risk-Based Review Cadence
A scheduled, recurring review of security policies, timed by each policy's risk level and organization-defined frequency rather than a fixed yearly rule, to confirm each one is still accurate, relevant, and aligned with current risks and regulations, updating or retiring those that are out of date.
Risk-Based Review Scope
Risk-based review scope selects identities and entitlements for certification according to privilege, data sensitivity, identity type, change history, external exposure, and likely business impact.
Risk-Based Step-Up Authentication
Risk-based step-up authentication requires stronger or fresh authentication when signals indicate that a particular sign-in or identity carries elevated risk.
Risk-Based Tuning
Tuning detections by the risk they address, focusing engineering time on rules covering the most relevant threats and tolerating noise where the underlying threat is critical enough to justify it.
Risk-Based Vulnerability Prioritization
Prioritizing vulnerability remediation by the real risk each one creates, exploitability, exposure, asset value, rather than treating all vulnerabilities by raw severity score.
Role
A named bundle of responsibilities or permissions assigned to identities under defined eligibility, ownership, review, and separation-of-duties rules.
Role Engineering
Role engineering derives maintainable organizational roles and permission mappings from authorized business operations, constraints, target semantics, and representative evidence.
Role Engineering Value
The benefits of designing roles deliberately, simpler administration, cleaner audits, stronger least privilege, that justify investing in role engineering rather than letting access grow ad hoc.