do you accept?

The easiest way to treat a risk is not to.

Risk acceptance is perfectly reasonable in many cases where it would be too expensive or even impossible to mitigate a risk. Exposing a system to the Internet carries substantial risk and yet we do so because that's where potential customers are.

Who has the authority to accept risk? It's down to policy, ownership of systems and ultimately management structures.

Risk acceptance should be a conscious, documented decision and not just lack of action.

