The easiest way to treat a risk is not to.
Risk acceptance is perfectly reasonable in many cases where it would be too expensive or even impossible to mitigate a risk. Exposing a system to the Internet carries substantial risk and yet we do so because that's where potential customers are.
Who has the authority to accept risk? It's down to policy, ownership of systems and ultimately management structures.
Risk acceptance should be a conscious, documented decision and not just lack of action.
(some of) my events
- 2021-09-21--23 Northern European Emergency and Disaster Studies (presenting at conference, Östersund)
- 2021-06-15--16 Stockholm Criminology Symposium (attending conference)
- 2021-03-29--06-04 Hållbar utveckling ur ett säkerhetsperspektiv (taking course, Karlstad University)
- 2021-01-18--06-04 Besluts- och riskanalys 3 (taking course, University of Gävle)
- 2021-01-14 Certifierad IT-arkitekt (guest lecturing, Stockholm)

Subscribe to:
Post Comments (Atom)
No comments:
Post a comment