A decision, action, or practice intended to reduce the level of risk associated with one or more threat events, threat scenarios, or vulnerabilities.
Source(s):
NIST SP 800-160 Vol. 2 Rev. 1