Accepting, avoiding, mitigating, sharing, or transferring risk to organizational operations (mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the Nation.
Sources:
NIST SP 800-137
under Risk Response
from
NIST SP 800-39
Accepting, avoiding, mitigating, sharing, or transferring risk to organizational operations (i.e., mission, functions, image, or reputation), organizational assets, individuals, other organizations, or the Nation. See Course of Action.
Sources:
NIST SP 800-30 Rev. 1
under Risk Response
from
NIST SP 800-39
Accepting, avoiding, mitigating, sharing, or transferring risk to organizational operations (i.e., mission, functions, image, or reputation), organizational assets, individuals, other organizations, or the Nation.
Sources:
CNSSI 4009-2015
from
NIST SP 800-39
NIST SP 800-160 Vol. 2 Rev. 1
from
NIST SP 800-39
NIST SP 800-39
under Risk Response
Accepting, avoiding, mitigating, sharing, or transferring risk to agency operations, agency assets, individuals, other organizations, or the Nation.
Sources:
NIST SP 800-37 Rev. 2
from
OMB Circular A-130 (2016)
NIST SP 800-53 Rev. 5
from
OMB Circular A-130 (2016)
NIST SP 800-53A Rev. 5
from
OMB Circular A-130 (2016)
Intentional and informed decision and actions to accept, avoid, mitigate, share, or transfer an identified risk.
Sources:
NIST SP 800-161r1
from
NIST SP 800-53 Rev. 5 - adapted
A way to keep risk within tolerable levels. Negative risks can be accepted, transferred, mitigated, or avoided. Positive risks can be realized, shared, enhanced, or accepted.
Sources:
NISTIR 8286
under Risk Response