Level of residual risk to the organization’s operations, assets, or individuals that falls within the defined risk appetite and risk tolerance by the organization.
Sources:
NIST SP 800-161r1-upd1
[11/1/2024 errata update]