Residual Risk

Residual risk is the risk that remains after security controls have been applied to an original, or inherent, risk. Because no control reduces the chance or impact of an event to zero, some exposure always survives, and that leftover exposure is what residual risk names.

The relationship is worth memorizing: inherent risk minus the effect of your controls equals residual risk. Once you reach that number, leadership has four options, to accept it, transfer it, mitigate further, or avoid the activity entirely. Formal sign-off matters here. Residual risk should be accepted in writing by a business owner with the authority to own the consequences, not quietly absorbed by the security team. A frequent error is confusing residual risk with total risk, or assuming that buying more tools drives it to zero. It never does, and past a point the cost of another control outweighs the risk it removes.

Why does residual risk matter for the CISSP exam?

It is central to Domain 1, Security and Risk Management. Expect questions on the risk treatment options, on who is authorized to accept risk, and on how residual risk fits the overall risk management lifecycle.