Difference between revisions of "Residual Risk"

From CIPedia
Jump to navigation Jump to search
(United States)
(DHS)
Line 41: Line 41:
 
=====[[DHS]]=====
 
=====[[DHS]]=====
 
{{definition|Residual risk is [[risk]] that remains after [[Risk Management|risk management]] [[Measure|measures]] have been implemented. <ref name="DHSLex"> [http://www.dhs.gov/xlibrary/assets/dhs-risk-lexicon-2010.pdf DHS Risk Lexicon 2010 Edition, September 2010]</ref>}}<br />
 
{{definition|Residual risk is [[risk]] that remains after [[Risk Management|risk management]] [[Measure|measures]] have been implemented. <ref name="DHSLex"> [http://www.dhs.gov/xlibrary/assets/dhs-risk-lexicon-2010.pdf DHS Risk Lexicon 2010 Edition, September 2010]</ref>}}<br />
<br />
 
  
 
=====[[NIST]]=====
 
=====[[NIST]]=====

Revision as of 00:02, 28 October 2017

Definitions

European Definitions

ENISA

ENISA uses the ISO definition, see below. [1]


Other International Definitions

UNISDR

The risk that remains in unmanaged form, even when effective disaster risk reduction measures are in place, and for which emergency response and recovery capacities must be maintained. [2]

According to UNISDR, the presence of residual risk implies a continuing need to develop and support effective capacities for emergency services, preparedness,response and recovery together with socio-economic policies such as safety nets and risk transfer mechanisms.

Risque résiduel: Les risques qui restent non gérés même si l’efficacité des mesures de réduction des risques de catastrophe est en place, et pour lesquels les interventions d’urgence et les capacités de récupération doivent être maintenues. [3]


Остаточный риск: Риск, который не поддается управлению даже после эффективной реализации мер по снижению риска, для противодействия которому необходимо сохранять потенциал реагирования и восстановления. [4]


Riesgo residual: El riesgo que todavía no se ha gestionado, aún cuando existan medidas eficaces para la reducción del riesgo de desastres y para los cuales se debe mantener las capacidades de respuesta de emergencia y de recuperación. [5]


المخاطر المتبقية : المخاطر التي لم يتم التحكم بها حتى بعد تطبيق الإجراءات الفعالة للحد من مخاطر الكوارث، والتي يجب المحافظة معها على قدرات الاستجابة والتعافي في حالات الطوارئ. [6]


Risiko Residual: Risiko yang tetap ada dalam bentuk yang tidak bisa dikelola, meskipun sudah ada langkahlangkah pengurangan risiko bencana yang efektif, dan yang mengharuskan tetap dijaganya kapasitas respons keadaan darurat dan pemulihan. [7]


Sisa Risiko: Risiko yang tertinggal dalam bentuk yang tidak diuruskan, walaupun tindakan pengurangan risiko bencana dilaksanakan, dan oleh sebab itu, respon kecemasan serta kapasiti pemulihan perlu dikekalkan. [8]


Mga Labing (Tirang) Peligro: Ang nalalabing peligro sa di-napamahalaang anyo (porma), kahit na mayruong mga hakbang sa pagbabawas ng peligro ng kalamidad, ay pagkakalooban pa rin ng pangkagipitang pagtugon at ang mga kakayahan sa pagrekober ay mamantinihin. [9]



National Definitions

Canada

Residual risk: risk that remains after implementing risk mitigation measures.

Risque résiduel: risque qui subsiste après l’application de mesures d’atténuation du risque. [10]



Risque résiduel: risque qui subsiste après la mise en œuvre de mesures de réduction des conséquences et des fréquences d’occurrence des accidents potentiels. [10]



Colombia

Riesgo Residual: Remanente después del Tratamiento del Riesgo. (GTC137 2011). Es aquel que permanece aún después de desarrolladas las acciones de tratamiento del riesgo. [11]

Capacidad total de riesgo que una organización está dispuesta a aceptar, tolerar o asumir en cualquier momento dado.

Czech Republic

Zbytkové riziko: Riziko, které zůstává i po aplikaci příslušných opatření. [12]

Residual risk is the risk remaining even after an application of the appropriate measures. [13]


Japan

残存リスク: 対策が適用された後に残るリスク.

The risk that remains after countermeasures have been applied. [14]



Luxembourg

Risque résiduel: Risque subsistant après le traitement des risques. [15]



Philippines

Residual Risk: The remaining potential risk after all IT security measures are applied. [16]



Portugal

[Definição]Risco Residual: Risco que permanece após terem sido aplicadas medidas de segurança, dado que não é possível neutralizar todas as ameaças nem eliminar todas as vulnerabilidades. [17]



Switzerland

Restrisiko bezeichnet das Risiko, das nach Realisierung aller vorgesehenen Sicherheitsmassnahmen weiterhin verbleibt. [18]

On entend par « risque résiduel » le risque qui subsiste une fois que toutes les mesures de sécurité prévues ont été mises en oeuvre. [19]

È il rischio che rimane dopo l'adozione di tutte le misure di sicurezza previste. [20]




United States

DHS
Residual risk is risk that remains after risk management measures have been implemented. [21]


NIST
The potential for the occurrence of an adverse event after adjusting for the impact of all in-place safeguards. (from: NIST SP 800-16) [22]


The remaining potential risk after all IT security measures are applied. (from: NIST SP 800-16) [22]

There is a Residual risk associated with each threat.

Standard Definition

IETF

The portion of an original risk or set of risks that remain after countermeasures have been applied. [23]


ISO/IEC 27000:2014 and ISO 31000:2009

Residual risk is the risk remaining after risk treatment. [24] [25]

  • Residual risk can contain unidentified risk.
  • Residual risk can also be known as “retained risk”.

See also

Notes