In ISO 27005 and NIST SP 800-53 RA-7 terms, what are the risk treatment options, and who may accept the residual risk?
answer
- reduce, hand off, stop, or keep
- transfer moves money, not accountability
- acceptance is a signed decision
- owner with authority, not the finder
basics
~20 sRisk can be mitigated (ISO 27005: modified), transferred or shared, avoided, or accepted (retained). Residual risk may be accepted only by a risk owner with authority to bear it, documented with rationale and a review date.
solid answer
~50 sThe options are the same in both vocabularies. **Mitigate** (ISO 27005: *modify*) adds or strengthens controls to reduce likelihood or impact. **Transfer or share** moves part of the consequence to another party through insurance or contract, but the organization stays accountable for the harm. **Avoid** stops the activity that creates the risk. **Accept** (*retain*) is an informed decision to keep the risk, which NIST SP 800-53 `RA-7` says needs "appropriate justification or rationale". `RA-7` also says that when mitigation cannot be completed immediately, a POA&M entry is generated. Acceptance belongs to the **risk owner** with authority over the activity: ISO 27001 has risk owners approve the treatment plan and accept residual risk, and in the NIST RMF the authorizing official's acceptance of risk is the one activity that cannot be delegated to a designated representative.
go deeper
Name the four options in both ISO and NIST words and say who is allowed to accept residual risk: a risk owner with authority, not the person who found it.
Explain what each option changes, why transfer never moves accountability, and why acceptance needs rationale and a review date. Know that open mitigation becomes a POA&M entry under RA-7.
Show how you structure acceptance authority by risk level, handle an acceptance request above tolerance, and stop acceptances turning into permanent neglect.
Discuss when avoidance beats mitigation strategically and how insurance limits, contracts and controls combine into a treatment portfolio the board understands.
## The options, in each vocabulary Every assessed risk ends in a **treatment** (ISO vocabulary) or **risk response** (NIST vocabulary) decision. The names differ, the substance does not. | Substance | ISO/IEC 27005 | NIST SP 800-30 / SP 800-53 `RA-7` | NIST CSF 2.0 | |---|---|---|---| | Reduce likelihood or impact with controls | Modify | Mitigate | Mitigating | | Move part of the consequence to another party | Share | Share or transfer | Transferring | | Stop the activity that creates the risk | Avoid | Avoid | Avoiding | | Knowingly keep the risk | Retain | Accept | Accepting | SP 800-30 lists the responses as "risk acceptance, avoidance, mitigation, sharing, or transfer". CSF 2.0 adds that positive risks (opportunities) can be realised, shared, enhanced or accepted, which is outside the scope of most security registers. ## What each option really means - **Mitigate / modify.** New or stronger controls: MFA on an admin console, network segmentation, backups tested for restore. `RA-7`'s discussion: "mitigating risk by implementing new controls or strengthening existing controls". If the work cannot be done at once, a **plan of action and milestones** entry tracks it. - **Transfer / share.** Cyber insurance, contractual indemnities, outsourcing a function to a provider with its own controls. Only part of the consequence moves: an insurer can pay for response costs, but it cannot restore customer trust or take on the organization's regulatory obligations. Accountability for the harm never leaves the organization. - **Avoid.** Remove the activity: do not store raw card data, retire a legacy integration, drop a feature in a high-risk market. Avoidance is often the cheapest option and the most often overlooked. - **Accept / retain.** A deliberate, documented decision that the risk is within tolerance or that treatment costs more than it saves. Acceptance is not ignoring: the row stays in the register, has a rationale and is reviewed. Whatever is chosen, some risk remains. SP 800-37 Rev. 2 puts it directly: "regardless of the risk response, there remains a degree of residual risk", and organizations determine acceptable degrees of residual risk based on risk tolerance. ## Who may accept residual risk Acceptance is the decision that most needs the right person, because it is the one that leaves harm on the table. 1. **The risk owner.** ISO 27001 requires the organization to obtain the risk owners' approval of the risk treatment plan and their acceptance of the residual information security risks. The risk owner is the person with accountability and authority to manage that risk, usually a business manager. 2. **Within delegated limits.** Most programmes tie acceptance authority to the size of the residual risk: a team lead can accept low risks, a business-unit head moderate ones, and anything above the organization's tolerance goes to executive level. 3. **In the NIST RMF, the authorizing official.** SP 800-37 Rev. 2 defines authorization as a senior official's decision to operate a system and "explicitly accept the risk", and says the only activity the authorizing official cannot delegate to the designated representative is the authorization decision and signing it, "the acceptance of risk". Who may *not* accept: the engineer who found the issue, the security team on the business's behalf, or anyone who closes a ticket as "won't fix" without authority. Those are the patterns that turn acceptance into silent neglect. ## A fintech example A fintech finds that its partner-bank file transfer uses a shared credential. - *Mitigate*: move to per-partner keys, tracked with a date. - *Transfer*: none meaningful; insurance would not restore settlement. - *Avoid*: not possible without losing the partner. - *Accept*: the head of treasury operations accepts the residual risk for the six weeks until migration, with a written rationale and a review on the migration date. ## Common mistakes - Calling insurance a complete answer to a risk. - Treating "accept" as the default when nobody decides. - Letting acceptances live forever with no review date. - Believing every risk must be mitigated to zero, which no treatment achieves.
- Does buying cyber insurance transfer a ransomware risk completely?No. Insurance transfers part of the financial consequence, typically response, recovery and some liability costs, up to the policy limits and subject to exclusions. The outage, the customer harm, the regulatory obligations and the reputational damage stay with the organization, so the risk row keeps its owner and a residual rating that reflects what the policy does not cover.
- Under NIST SP 800-53 RA-7, when does a risk response generate a POA&M entry?When the chosen response is to mitigate and the mitigation cannot be completed immediately. `RA-7` notes that a response may be to accept or reject the risk, or to mitigate it at once so no POA&M entry is needed; otherwise the open mitigation work is tracked as a plan of action and milestones entry until it is done.
Treatment is like deciding about a leaky roof: repair it (mitigate), buy insurance for water damage (transfer, though you still live in the wet house), move out (avoid), or put a bucket down and check it weekly (accept). Only the homeowner can choose the bucket.
saying these in an interview costs you the question
- Transferring a risk to an insurer or vendor removes accountability for it.
- Accepting a risk means taking no further notice of it.
- Any engineer can accept a risk by closing the ticket as won't fix.
- Every risk must be mitigated until nothing remains.
- Avoiding a risk means leaving it out of the register.