Accepting, avoiding, mitigating, sharing, or transferring risk to organizational operations (mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation.
Source(s):
NIST SP 800-137
under Risk Response
from
NIST SP 800-39
Accepting, avoiding, mitigating, sharing, or transferring risk to organizational operations (i.e., mission, functions, image, or reputation), organizational assets, individuals, other organizations, or the Nation. See Course of Action.
Source(s):
NIST SP 800-30 Rev. 1
under Risk Response
from
NIST SP 800-39
Accepting, avoiding, mitigating, sharing, or transferring risk to organizational operations (i.e., mission, functions, image, or reputation), organizational assets, individuals, other organizations, or the Nation.
Source(s):
CNSSI 4009-2015
from
NIST SP 800-39
NIST SP 800-160 Vol. 2
from
NIST SP 800-39
NIST SP 800-39
under Risk Response
NIST SP 800-53 Rev. 4
[Superseded]
under Risk Response
Accepting, avoiding, mitigating, sharing, or transferring risk to agency operations, agency assets, individuals, other organizations, or the Nation.
Source(s):
NIST SP 800-37 Rev. 2
NIST SP 800-53 Rev. 5
from
OMB Circular A-130 (2016)
A way to keep risk within tolerable levels. Negative risks can be accepted, transferred, mitigated, or avoided. Positive risks can be realized, shared, enhanced, or accepted.
Source(s):
NISTIR 8286
under Risk Response