Unit 1 ยท Security foundations and risk
Risk analysis turns a threat model into decisions. A qualitative matrix can multiply likelihood and impact categories, but the result is not mathematical truth. Record evidence, uncertainty, dependencies, and time horizon. A risk owner accepts responsibility for treatment and residual risk; security staff advise and verify rather than silently owning every business decision.
Inherent risk: likelihood 4 x impact 5 = high
Treatment: MFA + anomaly detection + recovery test
Residual risk: likelihood 2 x impact 5 = mediumAvoidance removes the risky activity. Mitigation reduces likelihood or impact. Transfer moves some financial consequence, but not accountability. Acceptance is a conscious decision within risk appetite, with an expiry or review date. Reassess when systems, threats, regulations, or business impact change.
1. What does mitigation do?
2. Is risk acceptance the same as ignoring risk?
Useful measures include MFA coverage, time to revoke access, critical vulnerability age, tested restore time, unauthorized access attempts, and control-test results. A register should name an accountable owner and review date; a treatment is incomplete until evidence shows the risk changed.