The Risk State Vault — 3 Readings We Track
Every risk gets measured three times, before and after you act on it.
🔓
INHERENT RISK
Raw exposure. No controls applied yet.
🛡️
CONTROL RISK
Chance the controls themselves fail or gap out.
💧
RESIDUAL RISK
What's left over after controls do their job.
What senior management actually watches isn't the residual risk number itself — it's how that number is changing over time.
Risk Cuts Both Ways
Risk is the effect uncertainty has on your objectives — that effect isn't always a loss.
⚠️
NEGATIVE RISK
The classic downside — loss, damage, disruption.
🚀
POSITIVE RISK
Upside you miss by playing it too safe.
Unknown Risk — New or Changed Infrastructure
Stand up a new system, or materially change an existing one, and you're carrying risk nobody has measured yet.
🏗️
NEW OR
CHANGED INFRA
CHANGED INFRA
→
❓
UNKNOWN
RISK
RISK
→
✅
ASSESSED
BEFORE GO-LIVE
BEFORE GO-LIVE
Anatomy of a Risk Scenario
A scenario is a specific, hypothetical story — not an abstract worry.
⚡
THREAT
+
🎭
THREAT
ACTOR
ACTOR
+
🕳️
VULNER-
ABILITY
ABILITY
+
💾
ASSET
=
💥
BUSINESS
IMPACT
IMPACT
⚡
Threat — the potential event itself: a breach, a fire, an outage. What could happen.
🎭
Threat actor — who or what would actually cause it: a hacker, an insider, a competitor, nature itself.
🕳️
Vulnerability — the weakness that lets the threat actually happen: an unpatched system, a gap in a control, an untrained employee.
💾
Asset — the thing worth protecting: data, a system, people, money, reputation.
💥
Business impact — what actually happens to the business if the threat exploits that vulnerability against that asset.
Scenario analysis is the next step: estimating how likely that event actually is. The scenario describes what could happen; the analysis puts a likelihood on it.
Does a Change Always Need a Pentest?
Mostly — not literally always.
Standards like PCI DSS (11.4.2 / 11.4.3) require a penetration test after a significant change to infrastructure — that's the actual trigger, not "any" change.
Significant change → penetration test. Minor, low-risk change → a vulnerability scan or config review is often enough. The risk assessment decides which one applies.
CAPACITY — the hard ceiling. Max risk the org can absorb before it threatens survival.
APPETITE — the amount and type of risk the board chooses to pursue, set inside capacity.
TOLERANCE — acceptable wobble room around the appetite line.
THRESHOLD — the trip-wire inside tolerance that triggers escalation.
Risk Profile — The Current Readout
Not a limit like the others — it's the point-in-time snapshot of every risk the org is carrying right now, pulled from the risk register.
You hold the profile up against the appetite line to see whether the mission is running hot or cold.
None of this lives as tribal knowledge — the risk policy is the document that formally defines the organization's appetite and tolerance levels.
Track it continuously — KRIs are the early-warning radar that tell you when the profile is drifting toward the threshold.
4 Domains = 4 Station Decks
Each deck has a job. Each is weighted on the exam.
1
GOVERNANCE DECK
26% of exam
Strategy, org structure, policy, risk culture, ERM alignment to business goals.
2
RISK ASSESSMENT BAY
22% of exam · forward-looking
Identify threats & vulnerabilities, analyze, build the risk register.
3
RISK RESPONSE & REPORTING HUB
32% of exam — biggest deck
Treatment plans, control design, KRIs/KCIs, dashboards to leadership.
4
TECH & SECURITY ENGINEERING
20% of exam
SDLC, data mgmt, BCP/DR, security frameworks, emerging tech risk.
Risk Owner — The Gatekeeper
"No risk moves without my sign-off."
Every risk needs one accountable name — not a committee, not 'IT'.
Risk ownership means mapping each identified risk to a specific, named process owner. That owner accepts, funds, and answers for the response decision — and is accountable for the losses if the impact actually happens. Practitioners advise; owners decide.
Defense in Layers
Multiple control layers · multiple chances to catch the risk
Risk Heat Map
Likelihood × impact. Plot it, then work the red corner first.
IMPACT →
LOWLIKELIHOODHIGH
Dots = example risks plotted from the register. The higher-right a risk sits, the sooner it needs a response.
Fail Secure, Escalate Fast
🚨
"When telemetry goes quiet, assume the worst and report up."
If a control's status is unknown, treat the risk as unmitigated until proven otherwise. Silence is not assurance.
Control Owner — The Mechanic
🔧
"I KEEP THE CONTROL RUNNING."
Risk owners decide what to do. Control owners make sure it actually works day to day.
Accountable for implementing, operating, and testing one specific control — patches it, maintains it, reports the moment it fails. Often a different person from the risk owner.
Three Lines Model — Who Watches the Risk
Cross a line, the accountability changes. Same idea as a trust boundary, applied to people.
1ST LINE · OWN IT (Ops)
2ND LINE · OVERSEE IT (Risk & Compliance)
3RD LINE · ASSURE IT (Internal Audit)
Runs the mission day to daySets policy, watches the gaugesIndependently checks everyone's work, after the fact
Governance Documents — From Policy to Guidance
Four layers, each one more specific — and less mandatory — than the one above it.
📜
POLICY
→
📏
STANDARD
→
🔄
PROCESS
→
💡
GUIDANCE
📜
Policy — a high-level statement of management intent. Mandatory, sets the "why," approved by leadership and rarely changes.
📏
Standard — mandatory, specific requirements that support the policy. Standards are the minimum requirement for controls — the floor, not the ceiling.
🔄
Process — step-by-step instructions for how to actually meet the standard. Mandatory and operational.
💡
Guidance — recommended, not mandatory. Best-practice advice you're free to adapt.
Risk Sequence — The Flight Path
Same order every time. Step 5 only fires when it has to.
1
🔍
IDENTIFY
Find the risk, log it in the register.
→
2
📊
ASSESS
Rate likelihood & impact.
→
3
🛡️
EVALUATE CONTROLS
What's already catching this?
→
4
🎯
TREAT
Implement or recommend a response.
→
5
📣
ESCALATE
If it's outside your authority or tolerance.
Risk Treatment Options — The 4 T's
Risk = Likelihood × Impact
Mitigation rule: only spend on a control if it costs less than the loss it prevents. Cost-benefit decides the response, not instinct.
T
TREAT
aka MITIGATE
Add controls, reduce it to an acceptable level.
T
TOLERATE
aka ACCEPT
Take it as-is, it's inside appetite.
T
TRANSFER
aka SHARE
Insurance, contracts, third party.
T
TERMINATE
aka AVOID
Stop the activity causing it.
Exam questions often use the second label instead of the "T" — mitigate / accept / transfer / avoid are the same four options.
5 Control Types — Your Crew
🚧
PREVENTIVE
Stops the incident before it starts.
🔭
DETECTIVE
Spots it while it's happening.
🛠️
CORRECTIVE
Fixes it after the fact.
🛑
DETERRENT
Makes the attempt look not worth it.
🔁
COMPENSATING
Backup plan when the main control can't run.
Risk Universe — Know Your Threats
S
🪐
STRATEGIC
"Your plan aimed wrong."
O
⚙️
OPERATIONAL
"A process broke down."
F
💸
FINANCIAL
"It cost you more than planned."
C
📋
COMPLIANCE
"You broke a rule you agreed to."
R
📰
REPUTATIONAL
"Now everyone's watching."
T
🛰️
TECHNOLOGY
"The system itself gave way."
Recovery Timeline — RTO, RPO, SDO, MTO & AIW
Same story every disruption: something breaks, you scramble to a bare-minimum service level, you hold there, then you claw your way back to normal. These five terms are the checkpoints along that road.
🎚️
SDO — Service Delivery Objective: the minimum acceptable level of service you're aiming for during alternate processing. Not normal operations, just enough to survive.
⏱️
RTO — Recovery Time Objective: how long you have to get back up to that SDO level after the disaster hits.
⏪
RPO — Recovery Point Objective: how far back your data can afford to be lost, measured backward from the disaster to your last good backup. It's about data, not downtime.
⏳
MTO — Maximum Tolerable Outage: how long you can keep running in that degraded, alternate-processing state before the damage becomes unacceptable.
📅
AIW — Allowable Interruption Window: the whole stretch the business can tolerate being disrupted, disaster to full recovery. RTO plus MTO combined.
RPO looks backward, at how much data you can afford to lose. RTO and MTO look forward, at how long you can afford to be down. Same disaster, two different clocks.
Mission Facts — Commonly Missed
✍️
NON-REPUDIATION
Proof someone can't deny an action — signatures, logs, timestamps.
📝
EXCEPTION MANAGEMENT
Sign-off + compensating control + expiry date, when policy can't be followed.
👥
PEER REVIEW
A second qualified person checks the work before or after it ships.
💼
BUSINESS CASE
The mitigation activity plus its cost-benefit analysis — what actually gets a risk mitigation plan funded and implemented.
🗺️
RISK MITIGATION PLAN
Spells out the specific actions, owner, and timeline for reducing a risk to an acceptable level — what "Treat" looks like on paper.
🧾
AUDIT TRAIL
A log capturing who did what, and when — the record that makes accountability enforceable, not just claimed.
🏢
ENTERPRISE ARCHITECTURE's BIGGEST WIN
Effective operation — the org runs the way it was actually designed to.
⛓️
BLOCKCHAIN's TOP RISK
Lack of review of the underlying code — flaws become permanent once deployed.
Cracking Exam Questions — The Meaning of Determiners
The qualifier word in the question is the actual question. Spot it before you read the options.
BEST
Points to issues to fix — several options may help, but one actually resolves the underlying problem.
MOST
Points to what's mandatory or regular — the thing that's required, or that happens routinely.
GREATEST
All four options might be genuinely good — pick the one that covers the rest of them.
FIRST
It's about sequence — what happens before everything else, not what matters most.
MAIN / PRIMARY
Look for the outcome — the end result the activity is actually there to produce.
Mission Log — Memory Mnemonics
- GRT = domain order: Governance, Risk assessment, Risk response & reporting, Technology & security.
- Capacity is the hull limit, appetite is the course you set inside it, tolerance is how far you can drift, threshold is the alarm bell.
- Risk assessment looks forward — what could happen. Audit looks backward — what already did.
- Positive risk isn't a typo — it's the upside you lose by being too cautious, not just a downside avoided.
- KRI = fuel level sensor, warns before it empties. KCI = check on the control itself. KPI = speedometer, measures normal performance.
- Residual = Inherent − what the controls actually caught. Never assume it's zero.
- Mitigate only pays off if the control costs less than the risk it removes — that's the whole cost-benefit test.
- New or changed infrastructure carries unknown risk until someone actually assesses it — change management should trigger that before go-live, not after.
- A pentest is required after a significant change (that's the PCI DSS trigger) — not automatically for every change. Scale the test to the risk.
- Policy → standard → process → guidance: each layer gets more specific and less mandatory. Standards are the minimum requirement for controls, not the ceiling.
- No audit trail, no proof of accountability — the log of who did what is the only thing that makes "accountable" actually enforceable.
- Owners decide, practitioners advise. A risk with no named owner isn't managed — it's ignored.
Govern the mission. Assess the unknown. Respond with intent. Think like a risk owner.
CRISC INFOGRAPHIC · Domain weights per ISACA CRISC exam content outline · Study reference, not official ISACA material · Created by Máté Lendvai