Objective 2.4 · Lesson 1 of 2

Make risk decisions visible and accountable

A vulnerability programme needs more than scanners and patch tools. It needs agreed decision rights, measurable expectations, and controls that address the specific outcomes the organisation wants to prevent.

Classify how a control works and what it does

Administrative controls direct people and decisions through policies, assigned responsibilities, reviews, and procedures. Technical controls operate through systems, such as access restrictions or detection rules. Physical controls protect tangible access, such as a locked equipment room. These types describe implementation, not effectiveness. A well-written policy can still fail if nobody follows it or checks whether it is working.

Function is a separate classification. Preventative controls seek to stop unwanted events; detective controls identify relevant activity; responsive controls support action during an event; corrective controls restore or repair the affected condition. One mechanism can support several functions depending on its use. Explain the behaviour being assessed rather than assuming every firewall or every log has a single universal purpose.

Distinguish the risk from its treatment

Inherent risk is the exposure considered before the relevant controls; residual risk remains after those controls are applied. Risk appetite expresses the organisation’s willingness to take risk in pursuing its objectives. Analysts supply evidence about likely consequences and control performance, while authorised leaders decide whether the remaining risk is acceptable. A low scanner count does not make that business decision unnecessary.

Mitigation reduces likelihood or impact. Avoidance stops the activity creating the risk. Transfer allocates specified consequences to another party, for example through an appropriate contract or insurance arrangement, but does not erase operational responsibility. Acceptance is a deliberate, documented decision to retain the risk. An ignored ticket is not meaningful acceptance, and outsourcing an application does not automatically remove its security exposure.

Turn policy into a measurable workflow

A policy states expectations and accountability; supporting procedures describe how assessments, changes, exceptions, and verification occur. Define service-level objectives for the programme, such as the proportion of urgent findings treated within an internally agreed period. Specify when the clock starts, the eligible population, treatment criteria, the measurement window, and how exceptions appear. Otherwise, teams can report incompatible success rates.

Review overdue work, repeat findings, failed controls, and exceptions with the people who can resolve competing priorities. Pair timeliness with verification and service-health measures so hurried closures are not rewarded. Where obligations or supplier terms affect decisions, involve the appropriate governance, procurement, or legal adviser. Keep technical evidence and approval records connected without presenting a generic course example as a binding rule.

Keep these points in mind

  • Classify control implementation separately from its preventative, detective, responsive, or corrective function.
  • Acceptance requires an authorised decision; residual risk remains after controls.
  • Programme objectives need definitions, denominators, verification, and exception visibility.

Pause and practise

An organisation stops offering an unsupported file-transfer feature, purchases limited incident-cost insurance, and adds a detection rule to a remaining service. Classify the treatments and explain one limitation.

Show a worked response

Removing the unsupported feature is avoidance of the risk created by that activity. Insurance transfers specified financial consequences, subject to its terms, while the detection rule mitigates risk by improving visibility. Neither insurance nor detection removes every operational consequence; the service owner still needs to evaluate and accept or further treat residual risk.

Next lesson →
← Module overview