CISSP GLOSSARY · RISK MANAGEMENT & GOVERNANCE

Risk appetite

The amount and type of risk leadership is willing to accept in pursuit of organisational objectives, set at board level and cascaded down as the boundary for every risk decision.

Risk appetite is the amount and type of risk an organisation’s leadership is willing to accept in pursuit of its objectives. It is set at board or executive level, expressed as a formal statement, and cascaded downwards so that every risk decision, from risk treatment choices to control spending, can be tested against one agreed boundary. A start-up chasing growth may declare a high appetite; a regulated bank declares a low one.

The distinction that decides exam answers is appetite versus tolerance. Appetite is strategic and broad: leadership’s overall willingness to take risk across the organisation. Risk tolerance is the acceptable deviation around a specific objective or metric, set closer to the operational level. Appetite says “we accept moderate risk when entering new markets”; tolerance says “no more than four hours of downtime per quarter”. Appetite is set once by governance; tolerance operationalises it per objective, and the residual risk left after controls must sit inside both.

Exam relevance: if a scenario asks who decides how much risk the organisation will accept, the answer is senior management or the board, never the security team. If a question contrasts a broad strategic statement with a measurable per-objective threshold, the statement is appetite and the threshold is tolerance. The nearest confusable is risk acceptance: acceptance is a treatment decision about one identified risk, while appetite is the standing boundary those decisions must respect.