Skip to content
atlas

Residual risk

The risk still left after controls are in place, because no protection removes danger completely.

Draft - this entry has not been reviewed yet.

Formal

The level of risk that remains once the chosen controls have been applied, which the risk owner must then either formally accept or treat further.

In plain English

Even with a seat belt, driving still carries some chance of getting hurt.

In practice

After a municipality adds MFA and awareness training, phishing drops from red to yellow on its heat map, and the municipal director signs off that the yellow level left over is acceptable.

Why it matters

Pretending controls make risk vanish hides the danger that remains; naming it forces a named person to accept it or pay to reduce it further.

Technical deep dive

ISO Guide 73:2009 (since replaced by ISO 31073:2022) defines residual risk as risk remaining after risk treatment, with two notes that are often forgotten: residual risk can contain unidentified risk, and it is also known as retained risk. The first note is why "zero residual risk" is never a credible entry in a register; whatever was missed in risk identification is by definition still there. ISO/IEC 27001:2022 clause 6.1.3 f) makes residual risk a formal governance object: the organisation must obtain the risk owners' approval of the risk treatment plan and their acceptance of the residual information security risks, and auditors check that this approval exists and is signed by someone with authority over the risk.

In a register residual risk is the counterpart of inherent (gross) risk, the level assessed as if no controls, or only baseline controls, existed. Residual risk is then estimated by applying the expected effect of each control to likelihood, impact or both. That estimate carries two assumptions that frequently fail: that the control is designed to address the scenario, and that it is actually operating. An MFA policy with legacy protocols still allowed, or backups that have never been restored in a test, reduce residual risk on paper only. Organisations with mature programmes therefore tie residual scores to evidence from control testing, internal audit or ISO/IEC 27001 clause 9.1 measurements rather than to the fact that a control is listed.

Controls can also create secondary risks: a new EDR agent is a privileged component whose faulty update can take down every endpoint at once, and outsourcing a service shifts availability and confidentiality risk to a supplier relationship. ISO 31000:2018 clause 6.5.2 explicitly notes that treatment can introduce new risks that must themselves be managed, so the residual picture is the old risk after treatment plus any new ones.

Residual risk is evaluated against the risk acceptance criteria and appetite. If it lies within them, it can be accepted and recorded with an owner and review date; if not, the options are further treatment or an explicit, escalated decision to accept anyway. Showing inherent and residual scores side by side is also the most direct way to show leadership what the security budget bought.

What to learn first

Everything this builds on, foundations first.

  1. CIA triad
  2. →Threat
  3. →Asset
  4. →Vulnerability
  5. →Impact
  6. →Likelihood
  7. →Risk
  8. →Security control
  9. →Residual risk

Relationships

A kind of
Risk
Don't confuse with
Risk appetite

Sources & further reading

Standards & official texts

  • ISO/IEC 27005:2022

Course material

  • Cyber Security Fast Track - Ordliste

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Check yourself

Loading…

Atlas is in beta.