A defined method is used to select and implement risk responses based on analysis and prioritization
The organization should develop a defined list of acceptable risk responses and the definition of each response. It may be necessary to define approvals that are necessary for certain risk response strategies, such as accepting a risk. Processes for other risk response strategies such as transference should also be considered to ensure that cyber risks have an individual responsible for tracking them to closure.
Related Practices · Progression: This practice is part of a practice progression. Practice progressions are groups of related practices that represent increasingly complete or more advanced implementations of an activity. The practices in this progression include: RISK-4a, RISK-4b, RISK-4e.