home/glossary/Risk mitigation

Risk mitigation

nounid 3927·updated Aug 30, 2026
verified· unreviewed

Prioritizing, evaluating, and implementing the appropriate risk-reducing controls/countermeasures recommended from the risk management process.

MWE

Attested in

NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems1 citation · 1 machine-matched · observed 2026-09-01 under anchor/0.9/36451/2026-09-01
03.16.02.b

Classifications

Entity Type

Control0%rule-basedmulti_axis_classifier_low_confidence.v1

Sensitivity

50%llm-generatedllm:claude-haiku-4-5

Information Class

60%llm-generatedllm:claude-haiku-4-5

Variants

plural
Risk mitigations
possessive
Risk mitigation's
pluralpossessive
Risk mitigations'

Framework definitions

ISACA Cybersecurity Glossary1 senseview framework →
§1
The management of risk through the use of countermeasures and controls
Federal Financial Institutions Examination Council (FFIEC) IT Examination Handbook Infobase, Glossary1 senseview framework →
§1
The process of reducing risks through the introduction of specific controls and risk transfer. It includes the implementation of appropriate controls to reduce the potential for risk and bring the level of risk in line with the board's risk appetite.
NISTIR 7298: Glossary of Key Information Security Terms, Revision 21 senseview framework →
§1
Prioritizing, evaluating, and implementing the appropriate risk-reducing controls/countermeasures recommended from the risk management process.
CNSSI-4009 (Glossary of Information Assurance Terms)1 senseview framework →
§1
Prioritizing, evaluating, and implementing the appropriate risk-reducing controls/countermeasures recommended from the risk management process.
NIST SP 800-301 senseview framework →
§1
Prioritizing, evaluating, and implementing the appropriate risk-reducing controls/countermeasures recommended from the risk management process.
NIST SP 800-391 senseview framework →
§1
Prioritizing, evaluating, and implementing the appropriate risk-reducing controls/countermeasures recommended from the risk management process.
NIST SP 800-171r31 senseview framework →
§1 · attested_usage_pack_match
No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
Legacy lexicon import1 senseview framework →
§1 · legacy_primary
Prioritizing, evaluating, and implementing the appropriate risk-reducing controls/countermeasures recommended from the risk management process.
DR-088 backfill from the noun definition column

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.