← CISM: manage security, risk, and incidents
04 / 8 · 30 MIN

Treat, monitor, and escalate risk

Keep risk decisions valid when deadlines, threats, and dependencies change.

Concept and mechanism

Risk treatment may involve changing controls, avoiding an activity, sharing consequences, or accepting exposure within defined authority. Acceptance should have scope, ownership, conditions, and review; a 30-day exception does not become permanent because no incident occurred. The risk owner tracks exposure and the decision; the control owner ensures execution and evidence of the mechanism. These responsibilities may be close without being identical. A KRI should connect to interpretation and action limits. If the threshold is ten expired exceptions and there are fourteen, report the breach and plan without turning the indicator into proof of fourteen incidents.

Guided application

In banking services, two contracts do not guarantee redundancy. Investigate shared dependencies, including subcontractors, identity, and connectivity. Testing each vendor separately may leave the failure affecting both untested. During a patch exception, track threat changes, demonstrate compensating controls, and present alternatives before validity expires. Active exploitation elsewhere justifies reassessing likelihood but does not prove local compromise. Maintain traceability between evidence, residual risk, decision, and next review. Escalating does not mean abandoning the problem: prepare options with operational impact, resources, timing, and exit criteria so the authorized person can decide.

IN PRACTICE

A network mitigation planned in a ticket remains unproven until evidence exists on the affected path.

Common pitfalls

Exception without expiry; duplicate vendor as independence; approved but unimplemented condition.

Related topics: Develop the security program · Manage controls, suppliers, and lifecycle

Take this idea with you

Keep the decision connected to the conditions that justified it.

Create account

Reference: Cybersecurity Framework 2.0 · CISM current outline before November 3, 2026