Risk tolerance
Term · Cybersecurity · MLC-T-CYB-003623
1. The level of risk an entity is willing to assume in order to achieve a potential desired result.
2. The level of risk or the degree of uncertainty that is acceptable to an organization.
3. The organization’s or stakeholder’s readiness to bear the remaining risk after responding to or considering the risk in order to achieve its objectives.
4. The organization or stakeholder’s readiness to bear the risk after risk treatment in order to achieve its objectives.
5. The readiness of an organization or stakeholders to bear the remaining risk after responding to or considering the risk to achieve its objectives (while recognizing that such tolerance can be influenced by legal or regulatory requirements)
6. The acceptable level of variance in performance relative to the achievement of objectives.
7. Risk tolerance is the degree of risk or uncertainty that is acceptable to an organization.
8. The level of risk that the Manufacturer is willing to accept in pursuit of strategic goals and objectives.
9. The level of risk or degree of uncertainty that is acceptable to organizations.
10. The organization’s or stakeholder’s readiness to bear the remaining risk after risk response in order to achieve its objectives, with the consideration that such tolerance can be influenced by legal or regulatory requirements.
| Identifier | MLC-T-CYB-003623 |
|---|---|
| Field | Cybersecurity |
| References | NIST SP 800-137; NIST SP 800-137A from NIST SP 800-137; NIST SP 800-53 Rev. 5 from NIST SP 800-39; NIST SP 800-53A Rev. 5 from NIST SP 800-39; NIST SP 800-161r1-upd1 [11/1/2024 errata update] from NISTIR 8286 (adapted); NIST SP 800-160v1r1 from ISO Guide 73; NIST SP 800-221; NIST SP 800-221 from OMB Circular A-123; NISTIR 8170; NISTIR 8183; NISTIR 8183 Rev. 1; NISTIR 8183A Vol. 1; NISTIR 8183A Vol. 2; NISTIR 8183A Vol. 3; NIST Privacy Framework Version 1.0 from NIST SP 800-39; NISTIR 8286 from ISO Guide 73; NIST CSRC Glossary |
Record as JSON
{
"id": "MLC-T-CYB-003623",
"term": "Risk tolerance",
"field": "Cybersecurity",
"definition": "1. The level of risk an entity is willing to assume in order to achieve a potential desired result.\n\n2. The level of risk or the degree of uncertainty that is acceptable to an organization.\n\n3. The organization’s or stakeholder’s readiness to bear the remaining risk after responding to or considering the risk in order to achieve its objectives.\n\n4. The organization or stakeholder’s readiness to bear the risk after risk treatment in order to achieve its objectives.\n\n5. The readiness of an organization or stakeholders to bear the remaining risk after responding to or considering the risk to achieve its objectives (while recognizing that such tolerance can be influenced by legal or regulatory requirements)\n\n6. The acceptable level of variance in performance relative to the achievement of objectives.\n\n7. Risk tolerance is the degree of risk or uncertainty that is acceptable to an organization.\n\n8. The level of risk that the Manufacturer is willing to accept in pursuit of strategic goals and objectives.\n\n9. The level of risk or degree of uncertainty that is acceptable to organizations.\n\n10. The organization’s or stakeholder’s readiness to bear the remaining risk after risk response in order to achieve its objectives, with the consideration that such tolerance can be influenced by legal or regulatory requirements.",
"references": [
"NIST SP 800-137; NIST SP 800-137A from NIST SP 800-137",
"NIST SP 800-53 Rev. 5 from NIST SP 800-39; NIST SP 800-53A Rev. 5 from NIST SP 800-39",
"NIST SP 800-161r1-upd1 [11/1/2024 errata update] from NISTIR 8286 (adapted)",
"NIST SP 800-160v1r1 from ISO Guide 73",
"NIST SP 800-221",
"NIST SP 800-221 from OMB Circular A-123",
"NISTIR 8170",
"NISTIR 8183; NISTIR 8183 Rev. 1; NISTIR 8183A Vol. 1; NISTIR 8183A Vol. 2; NISTIR 8183A Vol. 3",
"NIST Privacy Framework Version 1.0 from NIST SP 800-39",
"NISTIR 8286 from ISO Guide 73",
"NIST CSRC Glossary"
],
"url": "https://mlchart.com/terminology/cybersecurity/risk-tolerance/"
}
Record 3,606 of 4,669 in Cybersecurity terminology (MLC-0102). Request the full dataset.