CISSP GLOSSARY · RISK MANAGEMENT & GOVERNANCE
Risk treatment
The decision on how to respond to an identified risk using one of four options: avoid it, transfer it, mitigate it, or accept it. Every identified risk gets exactly one deliberate response.
Risk treatment (also called risk response) is the decision phase of risk management: once a risk has been analysed, the organisation chooses one of four responses. Avoidance ends the activity that creates the risk. Transference shifts the financial consequence to a third party, classically through insurance or outsourcing contracts. Mitigation applies controls to reduce likelihood or impact. Acceptance is a documented, informed decision by leadership to carry the risk because treating it would cost more than the exposure justifies.
Two caveats decide questions. First, transference moves financial liability, not accountability: you can insure against a data breach, but the organisation still owns the legal and reputational consequences. Second, every response except avoidance leaves residual risk, which must be formally accepted and must sit within the organisation’s risk appetite. Acceptance is legitimate only when it is deliberate and documented; quietly ignoring a known risk is negligence, not acceptance.
Exam relevance: if a scenario mentions insurance, the answer is transference. If a project is cancelled because the risk is too great, that is avoidance; if controls are deployed, mitigation. The classic trap is “risk rejection”, which appears as a plausible fifth option and is never valid: refusing to acknowledge a risk is not a treatment. Distinguish acceptance (a conscious governance decision) from rejection (pretending the risk does not exist), and remember that due care requires the decision to be documented.