Day 2 — Afternoon · Domain 2 (20%)

Risk Management — Part B

Part B works the risk lifecycle in practice: identifying risk, analyzing it qualitatively and quantitatively, choosing a treatment, and monitoring and reporting it — always recommending to the business, never deciding for it.

Session: Afternoon, Day 2 Duration: ~3 hrs Exam Weight: 20% (Domain 2) Knowledge Check: 8 Questions

Overview

Identify, analyze, treat, monitor — and report

With the foundation set in Part A, Part B runs the lifecycle. The security manager identifies threats and vulnerabilities, analyzes the resulting risk (qualitatively, quantitatively, or both), and recommends a treatment — mitigate, transfer, avoid, or accept. The business chooses and accepts; the manager then monitors the residual risk with key risk indicators and reports it to leadership in business terms. The exam rewards the candidate who keeps treatment decisions with the business and frames everything around impact, not technology.

Learning Objectives

By the end of this lesson you will be able to…

Key Terms

Risk lifecycle vocabulary

👈 Tap a card to flip it. Know the analysis formulas and treatment options cold.

Lesson Content

Study the material

1

Identifying Risk

Objective 1 · identifying risk

Identification finds the threats and vulnerabilities that could harm assets. Risk exists only where a threat can exploit a vulnerability affecting a valued asset — all three must be present. Drawing on multiple sources avoids blind spots.

  • Threat sources: external attackers, insiders, third parties, and environmental/accidental events.
  • Inputs: threat intelligence, vulnerability assessments, audit findings, past incidents, and business change (new systems, M&A, suppliers).
  • Threat modeling structures the search by walking through how an asset could be attacked.
  • Identification is continuous — new assets, technologies, and threats appear constantly.
💡 Exam TipA vulnerability with no credible threat, or a threat with no exploitable vulnerability, is not (yet) a meaningful risk. Don’t let a long scan report drive priorities — risk requires threat, vulnerability, and a valued asset together.
2

Analyzing Risk: Qualitative vs. Quantitative

Objective 2 · risk analysis

Analysis turns identified risks into something the business can prioritize. Qualitative analysis rates likelihood and impact on a relative scale (a heat map); quantitative analysis puts a monetary figure on the risk. Mature programs use both — qualitative to triage, quantitative to justify spend on the biggest risks.

IMPACT → 51015202548121620369121524681012345 SevereMajorModerateMinorInsignificant RareUnlikelyPossibleLikelyAlmostCertain LIKELIHOOD → ! LowMediumHighExtreme
A qualitative risk is rated by likelihood × impact, and where it lands sets the priority. The plotted example — a likely event with major impact — sits in the extreme zone: it demands treatment, not acceptance.

The quantitative formulas

  • SLE = Asset Value × Exposure Factor — loss from a single event.
  • ALE = SLE × ARO — expected loss per year.
  • A control is worth buying when its annual cost is less than the reduction in ALE it delivers (a positive return on security investment).
🔎 In practice

A server is valued at $200,000; a fire would destroy 50% of it (EF = 0.5), so SLE = $100,000. If a fire is expected once in 10 years (ARO = 0.1), ALE = $10,000/year. A suppression upgrade costing $3,000/year that largely removes the risk is clearly justified.

💡 Exam TipWhen the scenario lacks reliable numbers, qualitative analysis is the right call; when leadership needs to compare risk against control cost in dollars, quantitative is the better tool. Match the method to what the question provides.
3

Treating Risk

Objective 3 · risk treatment

Every analyzed risk gets a treatment decision. There are exactly four options, and the business selects among them on a cost-benefit basis bounded by risk appetite. The security manager recommends; the risk owner decides.

OptionWhat it meansExample
Mitigate / ReduceApply controls to lower likelihood or impactMFA, patching, segmentation, monitoring
Transfer / ShareShift the financial impact to a third partyCyber-insurance; outsourcing with strong SLAs
AvoidEliminate the risk by not doing the activityDiscontinue a risky feature, market, or technology
AcceptKnowingly retain a risk within appetiteFormal, documented sign-off by the risk owner
💡 Exam TipInsurance and outsourcing are forms of risk transfer — but they move financial impact, not accountability. The organization still owns the risk and the regulatory and reputational consequences.
4

Acceptance & Residual Risk

Objective 4 · acceptance and residual

After treatment, some risk always remains — the residual risk. The business compares it to appetite and either accepts it or invests further. Acceptance must be deliberate and documented, never the default that happens because no one decided.

  • Formal acceptance: the risk owner signs off, with rationale, a review date, and an entry in the register.
  • Residual risk above appetite must be reduced further, transferred, or avoided — not quietly accepted by the security team.
  • Exceptions (temporary deviations from policy) are risk acceptances with an expiry and an owner — track them, don’t let them become permanent.
  • Security recommends; the business accepts — the most-tested boundary in this domain.
🔎 In practice

A project wants to skip a required control to hit a deadline. The manager does not simply refuse or silently allow it — they document the residual risk and route it to the business risk owner for a formal, time-bound acceptance decision.

Try it — how much treatment is the right amount?

Put the four treatment options on one graph. Price the risk (ALE), then mitigate it: residual risk falls but control cost rises, and the total cost of risk is lowest somewhere in between. Watch residual against the business’s risk appetite — where it still sits too high, that’s where transfer, avoid, or a formal acceptance decision come in.

Interactive · adjust & explore
The risk decision

Price the risk, then decide how far to treat it.

The risk (annual loss exposure)
$2,000,000
Value at stake if the asset is compromised.
35%
Share of value lost per event. SLE = AV × EF.
0.40 / yr
Events per year. ALE = SLE × ARO.
The decision
$50,000
Annual loss the business is willing to carry.
70%
0% = accept · higher = mitigate more (costs more).
$15,000
How expensive this control is to run.
The economics
Inherent ALE
Residual risk
Treatment cost
Total cost of risk
Adjust the treatment to balance risk and cost.
Total cost of risk

As you mitigate more, residual risk falls and control cost rises — total cost of risk bottoms out at the economic optimum. The dashed line is the business’s risk appetite.

Residual risk Control cost Total cost of risk Risk appetite
🔎 In practice

This is a recommendation, not a decision. The security manager brings the business the numbers — residual risk, treatment cost, the total-cost-of-risk optimum — and the risk owner chooses to mitigate, transfer, avoid, or formally accept. Residual risk above appetite is never quietly accepted by the security team.

5

Monitoring & Reporting Risk

Objective 5 · monitoring and KRIs

Risk is not ‘done’ once treated. Conditions change, so the manager monitors residual risk and reports it to leadership in business terms, keeping the risk register current as the single source of truth.

  • KRIs give early warning that risk is rising, so leadership can act before an incident.
  • The risk register is maintained continuously — new risks added, treatments and owners updated, accepted risks reviewed at their due dates.
  • Reporting translates technical exposure into business impact and trends the board can act on — not raw vulnerability counts.
  • Monitoring closes the loop, feeding changes back into identification and analysis — the lifecycle is continuous.
💡 Exam TipIf a question asks how to keep leadership informed of changing risk, the answer involves KRIs and a current risk register reported in business terms — not a one-time assessment or a list of unpatched systems.

Scored Knowledge Check

Test your risk lifecycle judgment

Eight questions across identification, analysis, treatment, and reporting. Recommend as the manager; let the business decide.

Q1.Annual Loss Expectancy (ALE) is calculated as:

Question 1 options
Correct: A. ALE = SLE × ARO. (SLE itself = Asset Value × Exposure Factor.) ALE expresses the expected yearly loss so it can be compared with the annual cost of a control. Why the others fall short: B Asset Value × Exposure Factor is SLE; C and D aren’t the ALE formula — ALE is SLE × ARO.

Q2.An organization purchases cyber-insurance to cover potential breach costs. Which risk treatment is this?

Question 2 options
Correct: B. Buying insurance shifts the financial impact to a third party — risk transfer. It does not eliminate the activity (avoid), reduce likelihood (mitigate), or retain the risk (accept). Why the others fall short: A avoidance would end the activity; C mitigation would add controls; D acceptance would retain the risk — insurance shifts financial impact to a third party.

Q3.Reliable historical loss data is not available for a newly identified risk. Which analysis approach is MOST appropriate?

Question 3 options
Correct: D. Without dependable numbers, qualitative analysis (relative likelihood and impact, e.g., a heat map) is appropriate. Forcing quantitative figures on guesses produces false precision. Why the others fall short: A quantitative analysis needs the data that’s missing; B deferring leaves the risk unmanaged; C accepting by default skips analysis entirely.

Q4.Residual risk after treatment is found to exceed the organization’s risk appetite. What should the security manager do?

Question 4 options
Correct: C. Risk above appetite is not the security manager’s to accept. The manager recommends additional mitigation/transfer/avoidance and escalates the decision to the business risk owner. Why the others fall short: A the manager doesn’t accept risk on the organization’s behalf; B deleting it from the register hides the risk; D re-classifying to lower the value games the assessment.

Q5.Which of the following is NOT one of the four recognized risk treatment options?

Question 5 options
Correct: B. The four treatment options are mitigate, transfer, avoid, and accept. ‘Investigate’ is part of analysis, not a treatment decision. Why the others fall short: A mitigate, C transfer, and D avoid are three of the four options (with accept) — ‘investigate’ is not a treatment.

Q6.What is the PRIMARY purpose of a key risk indicator (KRI)?

Question 6 options
Correct: C. A KRI is forward-looking: it signals that risk is rising so leadership can act before an incident. It is distinct from a KPI, which measures current process performance. Why the others fall short: A confirming a control passed is a performance/assurance function; B SLE is a valuation calculation; D classifying an asset is unrelated to a KRI.

Q7.A business unit wants a temporary exception to a security policy to meet a deadline. The BEST course of action is to:

Question 7 options
Correct: A. An exception is a risk acceptance: document the residual risk and route it to the business risk owner for a formal decision with an expiry date — neither a flat refusal nor a silent allowance. Why the others fall short: B a flat refusal ignores a legitimate business need; C allowing it informally is undocumented risk acceptance; D deleting the requirement removes the control entirely.

Q8.Single Loss Expectancy (SLE) is calculated as:

Question 8 options
Correct: D. SLE = Asset Value × Exposure Factor, where the exposure factor is the percentage of the asset’s value lost in a single event. Why the others fall short: A SLE × ARO gives ALE; B and C aren’t valid formulas — SLE is Asset Value × Exposure Factor.