Part B works the risk lifecycle in practice: identifying risk, analyzing it qualitatively and quantitatively, choosing a treatment, and monitoring and reporting it — always recommending to the business, never deciding for it.
With the foundation set in Part A, Part B runs the lifecycle. The security manager identifies threats and vulnerabilities, analyzes the resulting risk (qualitatively, quantitatively, or both), and recommends a treatment — mitigate, transfer, avoid, or accept. The business chooses and accepts; the manager then monitors the residual risk with key risk indicators and reports it to leadership in business terms. The exam rewards the candidate who keeps treatment decisions with the business and frames everything around impact, not technology.
Learning Objectives
By the end of this lesson you will be able to…
Identify threats, threat sources, and vulnerabilities that create information risk. Bloom: Remember
Apply qualitative and quantitative risk analysis, including SLE, ARO, and ALE. Bloom: Apply
Select an appropriate risk treatment — mitigate, transfer, avoid, or accept — on a cost-benefit basis. Bloom: Evaluate
Explain formal risk acceptance and the handling of residual risk and exceptions. Bloom: Understand
Monitor and report risk using KRIs and a maintained risk register.
Key Terms
Risk lifecycle vocabulary
👈 Tap a card to flip it. Know the analysis formulas and treatment options cold.
Lesson Content
Study the material
1
Identifying Risk
Objective 1 · identifying risk
Identification finds the threats and vulnerabilities that could harm assets. Risk exists only where a threat can exploit a vulnerability affecting a valued asset — all three must be present. Drawing on multiple sources avoids blind spots.
Threat sources: external attackers, insiders, third parties, and environmental/accidental events.
Inputs: threat intelligence, vulnerability assessments, audit findings, past incidents, and business change (new systems, M&A, suppliers).
Threat modeling structures the search by walking through how an asset could be attacked.
Identification is continuous — new assets, technologies, and threats appear constantly.
💡 Exam TipA vulnerability with no credible threat, or a threat with no exploitable vulnerability, is not (yet) a meaningful risk. Don’t let a long scan report drive priorities — risk requires threat, vulnerability, and a valued asset together.
2
Analyzing Risk: Qualitative vs. Quantitative
Objective 2 · risk analysis
Analysis turns identified risks into something the business can prioritize. Qualitative analysis rates likelihood and impact on a relative scale (a heat map); quantitative analysis puts a monetary figure on the risk. Mature programs use both — qualitative to triage, quantitative to justify spend on the biggest risks.
A qualitative risk is rated by likelihood × impact, and where it lands sets the priority. The plotted example — a likely event with major impact — sits in the extreme zone: it demands treatment, not acceptance.
The quantitative formulas
SLE = Asset Value × Exposure Factor — loss from a single event.
ALE = SLE × ARO — expected loss per year.
A control is worth buying when its annual cost is less than the reduction in ALE it delivers (a positive return on security investment).
🔎 In practice
A server is valued at $200,000; a fire would destroy 50% of it (EF = 0.5), so SLE = $100,000. If a fire is expected once in 10 years (ARO = 0.1), ALE = $10,000/year. A suppression upgrade costing $3,000/year that largely removes the risk is clearly justified.
💡 Exam TipWhen the scenario lacks reliable numbers, qualitative analysis is the right call; when leadership needs to compare risk against control cost in dollars, quantitative is the better tool. Match the method to what the question provides.
📚
Explore furtherRisk Analysis and Threat Actors — interactive modules on analyzing risk and on the threat sources that drive it.
Every analyzed risk gets a treatment decision. There are exactly four options, and the business selects among them on a cost-benefit basis bounded by risk appetite. The security manager recommends; the risk owner decides.
Option
What it means
Example
Mitigate / Reduce
Apply controls to lower likelihood or impact
MFA, patching, segmentation, monitoring
Transfer / Share
Shift the financial impact to a third party
Cyber-insurance; outsourcing with strong SLAs
Avoid
Eliminate the risk by not doing the activity
Discontinue a risky feature, market, or technology
Accept
Knowingly retain a risk within appetite
Formal, documented sign-off by the risk owner
💡 Exam TipInsurance and outsourcing are forms of risk transfer — but they move financial impact, not accountability. The organization still owns the risk and the regulatory and reputational consequences.
4
Acceptance & Residual Risk
Objective 4 · acceptance and residual
After treatment, some risk always remains — the residual risk. The business compares it to appetite and either accepts it or invests further. Acceptance must be deliberate and documented, never the default that happens because no one decided.
Formal acceptance: the risk owner signs off, with rationale, a review date, and an entry in the register.
Residual risk above appetite must be reduced further, transferred, or avoided — not quietly accepted by the security team.
Exceptions (temporary deviations from policy) are risk acceptances with an expiry and an owner — track them, don’t let them become permanent.
Security recommends; the business accepts — the most-tested boundary in this domain.
🔎 In practice
A project wants to skip a required control to hit a deadline. The manager does not simply refuse or silently allow it — they document the residual risk and route it to the business risk owner for a formal, time-bound acceptance decision.
Try it — how much treatment is the right amount?
Put the four treatment options on one graph. Price the risk (ALE), then mitigate it: residual risk falls but control cost rises, and the total cost of risk is lowest somewhere in between. Watch residual against the business’s risk appetite — where it still sits too high, that’s where transfer, avoid, or a formal acceptance decision come in.
Interactive · adjust & explore
The risk decision
Price the risk, then decide how far to treat it.
The risk (annual loss exposure)
$2,000,000
Value at stake if the asset is compromised.
35%
Share of value lost per event. SLE = AV × EF.
0.40 / yr
Events per year. ALE = SLE × ARO.
The decision
$50,000
Annual loss the business is willing to carry.
70%
0% = accept · higher = mitigate more (costs more).
$15,000
How expensive this control is to run.
The economics
Inherent ALE
—
Residual risk
—
Treatment cost
—
Total cost of risk
—
——Adjust the treatment to balance risk and cost.
Total cost of risk
As you mitigate more, residual risk falls and control cost rises — total cost of risk bottoms out at the economic optimum. The dashed line is the business’s risk appetite.
Residual risk Control cost Total cost of risk Risk appetite
🔎 In practice
This is a recommendation, not a decision. The security manager brings the business the numbers — residual risk, treatment cost, the total-cost-of-risk optimum — and the risk owner chooses to mitigate, transfer, avoid, or formally accept. Residual risk above appetite is never quietly accepted by the security team.
5
Monitoring & Reporting Risk
Objective 5 · monitoring and KRIs
Risk is not ‘done’ once treated. Conditions change, so the manager monitors residual risk and reports it to leadership in business terms, keeping the risk register current as the single source of truth.
KRIs give early warning that risk is rising, so leadership can act before an incident.
The risk register is maintained continuously — new risks added, treatments and owners updated, accepted risks reviewed at their due dates.
Reporting translates technical exposure into business impact and trends the board can act on — not raw vulnerability counts.
Monitoring closes the loop, feeding changes back into identification and analysis — the lifecycle is continuous.
💡 Exam TipIf a question asks how to keep leadership informed of changing risk, the answer involves KRIs and a current risk register reported in business terms — not a one-time assessment or a list of unpatched systems.
Scored Knowledge Check
Test your risk lifecycle judgment
Eight questions across identification, analysis, treatment, and reporting. Recommend as the manager; let the business decide.