From the course: ISC2 Certified Information Systems Security Professional (CISSP) (2024) Cert Prep

Unlock this course with a free trial

Join today to access over 23,400 courses taught by industry experts.

Risk treatment

Risk treatment

- [Instructor] Once you complete a risk assessment for your organization, you're left with a prioritized list of risks that require your attention. Risk management, or risk treatment, is the process of systematically analyzing potential responses to each risk and implementing strategies to control those risks appropriately. No matter what risk you're managing, you have four basic options for addressing the situation. You can perform risk avoidance, risk transference, risk mitigation, and risk acceptance. When you avoid a risk, you change your organization's business practices so that you are no longer in a position where that risk can affect your business. In the last video, we performed a risk assessment of the risk that flooding posed to an organization's data center. If we choose to pursue a risk avoidance strategy for that risk, we might relocate our data center to a facility where there is no risk of flood damage. Transferring a risk attempts to shift the impact of a risk from…

Contents