home/dictionary/Residual risk

Residual risk

nounverified·updated May 9, 2026

The risk to the achievement of objectives that remains after management's response has been designed and implemented.

Framework senses

ISACA Cybersecurity Glossary1 senseview framework →
§1
The remaining risk after management has implemented a risk response
Federal Financial Institutions Examination Council (FFIEC) IT Examination Handbook Infobase, Glossary1 senseview framework →
§1
The amount of risk remaining after the implementation of controls.
NISTIR 7298: Glossary of Key Information Security Terms, Revision 22 sensesview framework →
§1
The remaining potential risk after all IT security measures are applied. There is a residual risk associated with each threat.
§2 · sense_2_pending_review
Portion of risk remaining after security measures have been applied.
CNSSI-4009 (Glossary of Information Assurance Terms)1 senseview framework →
§1
Portion of risk remaining after security measures have been applied.
NIST SP 800-301 senseview framework →
§1
Portion of risk remaining after security measures have been applied.
NIST SP 800-331 senseview framework →
§1
The remaining potential risk after all IT security measures are applied. There is a residual risk associated with each threat.
TSP Section 1001 senseview framework →
§1 · glossary
The risk to the achievement of objectives that remains after management's response has been designed and implemented.
Attribution from the CKI glossary mapping stage (glossary)
Legacy lexicon import1 senseview framework →
§1 · legacy_primary
The remaining potential risk after all IT security measures are applied. There is a residual risk associated with each threat.
DR-088 backfill from the noun definition column