Difference between revisions of "Risk Acceptance"

From CIPedia
Jump to navigation Jump to search
Line 1: Line 1:
 
==Definitions==
 
==Definitions==
 
=== European Definitions ===
 
=== European Definitions ===
<!--- ==== Council Directive 2008/114/EC ====  
+
====[[ENISA]]====
{{definition|The consideration of relevant [[threat]] scenarios, in order to assess the [[vulnerability]] and the potential [[impact]] of [[disruption]] or [[destruction]] of [[Critical Infrastructure|critical infrastructure]]. <ref> [http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=OJ:L:2008:345:0075:0082:EN:PDF Council Directive 2008/114/EC of 8 December 2008 on the identification and designation of European critical infrastructures and the assessment of the need to improve their protection.]</ref>}}
+
{{definition|Risk Acceptance concerns the communication of residual risks to the decision makers.  <ref name="ENISARA"> [https://www.enisa.europa.eu/activities/risk-management/current-risk/risk-management-inventory/rm-process/risk-acceptance ENISA Risk Acceptance]</ref>}}<br /><br>
--->
+
{{definition|Risk Acceptance is the potential that a given threat will exploit vulnerabilities of an asset [G.3] or group of assets and thereby cause harm to the organization.
 +
(ISO/IEC PDTR 13335-1). <ref name="ENISAGlos"> [http://www.enisa.europa.eu/activities/risk-management/current-risk/risk-management-inventory/glossary ENISA Risk Glossary]</ref>}}<br />
 
<!---
 
<!---
 
=== Other International Definitions ===
 
=== Other International Definitions ===
Line 32: Line 33:
 
[[Category:Risk]]
 
[[Category:Risk]]
 
[[Category:Analysis]]
 
[[Category:Analysis]]
{{#set:defined by=Australia|defined by=Czech Republic}}
+
{{#set:defined by=ENISA|defined by=Australia|defined by=Czech Republic}}

Revision as of 23:45, 20 July 2015

Definitions

European Definitions

ENISA

Risk Acceptance concerns the communication of residual risks to the decision makers. [1]



Risk Acceptance is the potential that a given threat will exploit vulnerabilities of an asset [G.3] or group of assets and thereby cause harm to the organization. 
(ISO/IEC PDTR 13335-1). [2]


National Definitions

Australia

Risk acceptance is an informed decision to accept the likelihood and the consequences of a particular risk. [3]


Czech Republic

Přijetí rizika: Rozhodnutí přijmout riziko. [4]

Risk acceptance: Decision to accept risk. [5]


Standard Definition

See also

Notes