Citations

Existing Citations

  • inherent risk : The risk that an activity would pose if no controls or other mitigating factors were in place (the gross risk or risk before controls). . . Inherent Risk = Cost × Threat (†735)
  • residual risk : The risk that remains after controls are taken into account (the net risk or risk after controls). . . . Residual Risk = Cost × Threat × Vulnerability. (†736)