Risk Acceptance
Noun · Security & Infosec
Definitions
A formal decision to tolerate a known security risk without fully remediating it, usually because the cost, feasibility, or business tradeoff makes immediate mitigation impractical. Risk acceptance should be explicit, time-bounded, and owned rather than left as silent neglect.
In plain English: A deliberate decision to live with a known security risk for now.
Example: "Leadership signed a risk acceptance for the unsupported scanner, but only until the vendor replacement project finished next quarter."