CISSP GLOSSARY · RISK MANAGEMENT & GOVERNANCE

Residual risk

The risk that remains after controls are applied. It can never reach zero, so leadership must formally accept whatever remains within the organisation's risk appetite.

Residual risk is the risk that remains after safeguards and controls have been applied to reduce total risk. The conceptual formula the exam uses is total risk minus the risk removed by controls (the controls gap) equals residual risk. Controls reduce likelihood or impact; they never eliminate either entirely, so some residual risk always exists. The goal of a security programme is not zero risk but residual risk that sits within the organisation’s risk appetite.

The distinction to hold is total (inherent) risk versus residual versus acceptable risk. Total risk is the exposure before any control exists. Residual risk is what is left once the chosen risk treatment is in place. Acceptable risk is the threshold leadership has agreed to live with. Crucially, accepting residual risk is a senior management decision: security practitioners recommend and implement controls, but only leadership can sign off on the risk that remains.

Exam relevance: if a scenario asks who accepts residual risk, the answer is senior management (or the owner of the asset), never the security manager or the auditor. If a question describes risk “after controls are applied”, it is asking about residual risk; risk “before any controls” is total or inherent risk, the nearest confusable. And if residual risk still exceeds appetite, the correct response is further treatment, not quiet acceptance.