home/dictionary/Residual risk

Residual risk

nouncandidate·updated May 9, 2026

The remaining potential risk after all IT security measures are applied. There is a residual risk associated with each threat.

Framework senses

ISACA Cybersecurity Glossary1 senseview framework →
§1
The remaining risk after management has implemented a risk response
Federal Financial Institutions Examination Council (FFIEC) IT Examination Handbook Infobase, Glossary1 senseview framework →
§1
The amount of risk remaining after the implementation of controls.
NISTIR 7298: Glossary of Key Information Security Terms, Revision 22 sensesview framework →
§1
The remaining potential risk after all IT security measures are applied. There is a residual risk associated with each threat.
§2 · sense_2_pending_review
Portion of risk remaining after security measures have been applied.
CNSSI-4009 (Glossary of Information Assurance Terms)1 senseview framework →
§1
Portion of risk remaining after security measures have been applied.
NIST SP 800-301 senseview framework →
§1
Portion of risk remaining after security measures have been applied.
NIST SP 800-331 senseview framework →
§1
The remaining potential risk after all IT security measures are applied. There is a residual risk associated with each threat.