← Security+: security and production decisions
07 / 7 · 25 MIN

Governance, risk, and suppliers

Turn findings into traceable risk decisions.

Concept and mechanism

A risk should describe asset, condition, event, and impact with reviewable assumptions. “Old server” is incomplete inventory rather than sufficient risk explanation. Quantitative assessments also depend on assumptions: per-event loss multiplied by expected frequency gives a mean value in the model, not a guaranteed prediction. High-impact risks and uncertainty do not disappear because the mean is low. Residual acceptance belongs to governance-defined authority with controls, limits, review, and treatment plan. A technician can supply evidence without being authorized to accept the impact.

Guided application

During procurement, confirm supplier evidence covers relevant service, period, and controls. An out-of-scope report does not demonstrate protection for a new service. For technical assessments, define targets, authorization, contacts, and stop conditions before testing; staging-production similarity does not expand authorization. Policy needs procedures specifying who does what and how completion is demonstrated. In committees, report exposure by criticality and due date: 95% patched can hide that every critical endpoint is among the remaining 5%. Reporting should support decisions about remaining risk.

IN PRACTICE

In the simplified model, €20,000 per occurrence × 0.25 occurrences/year = €5,000/year expected. Also present uncertainty, relevant potential impact, and controls rather than only the number.

Common pitfalls

Accepting risk without authority; extrapolating assurance; testing outside scope; removing assets from the denominator; confusing mean with maximum.

Related topics: Controls, identity, and cryptography · Threats, exposure, and priority

Take this idea with you

A sound decision states scope, owner, evidence, and review conditions.

Create account

Reference: Guide for conducting risk assessments · SY0-701 V7