Category: Security, Data, artificial-intelligence

Residual risk is the threat or vulnerability that remains after all risk treatment and remediation efforts have been implemented. Because they will always be present, the process of managing residual risk involves setting an acceptable threshold and then implementing programs and solutions to mitigate all risks below that threshold.

Inherent risk is the amount of risk within an IT ecosystem in the absence of controls and residual risk is the amount of risk that exists after cybersecurity controls have been implemented.

The primary difference between inherent and residual risk assessments is that the latter takes into account the influence of controls and other mitigation solutions.

When effective security controls are implemented, there is an obvious discrepancy between inherent and residual risk assessments.

Related Articles