Risk Acceptance

Noun · Security & Infosec

Definitions

  1. A formal decision to tolerate a known security risk without fully remediating it, usually because the cost, feasibility, or business tradeoff makes immediate mitigation impractical. Risk acceptance should be explicit, time-bounded, and owned rather than left as silent neglect.

    In plain English: A deliberate decision to live with a known security risk for now.

    Example: "Leadership signed a risk acceptance for the unsupported scanner, but only until the vendor replacement project finished next quarter."

Related Terms