From the course: Cert Prep: ISC2 Certified in Cybersecurity (CC)

Unlock this course with a free trial

Join today to access over 23,200 courses taught by industry experts.

Risk treatment

Risk treatment

- Once you complete a risk assessment for your organization, you're left with a prioritized list of risks that need your attention. Risk management or risk treatment is the process of analyzing potential responses to those risks and implementing strategies to control each risk appropriately. Now, no matter what risk you're managing, you have four basic options for addressing the situation. You can perform risk avoidance, risk transference, risk mitigation, or risk acceptance. When you avoid a risk, you change your organization's business practices so that you're no longer in a position where that risk can affect your business. In the last video, we performed a risk assessment of the risk that flooding posed to an organization's data center. If we chose to pursue a risk avoidance strategy for that risk, we might relocate our data center to a facility where there is no risk of flood damage. Transferring a risk attempts…

Contents