residual risk [English]
- riesgo residual (Spanish)
- risco residual (Portuguese)
- SF: managed risk
- BT: risk
n. ~ A level of risk that remains after factoring in efforts to reduce its likelihood or impact through risk mitigation.
- Information Security Handbook 2009. (†485 ): The risk that remains after controls are taken into account (the net risk or risk after controls). . . . Residual Risk = Cost × Threat × Vulnerability.
- Wikipedia (†387 s.v. residual risk): The risk or danger of an action or event, a method or a (technical) process that, although being abreast with science, still conceives these dangers, even if all theoretically possible safety measures would be applied (scientifically conceivable measures). The formula to calculate residual risk is (inherent risk) x (control risk) where inherent risk is (threats × vulnerability).
- CNSS-4009 (†730 p.60): Portion of risk remaining after security measures have been applied. (†1743)
- ISACA Glossary (†743 s.v. residual risk): The remaining risk after management has implemented a risk response. (†1797)