<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Risk Mitigation vs Risk Treatment in CGRC Study Group</title>
    <link>https://community.isc2.org/t5/CGRC-Study-Group/Risk-Mitigation-vs-Risk-Treatment/m-p/59632#M67</link>
    <description>&lt;P&gt;I've always understood risk &lt;STRONG&gt;&lt;EM&gt;mitigation&lt;/EM&gt;&lt;/STRONG&gt;&amp;nbsp;to itself be one of the four risk &lt;STRONG&gt;&lt;EM&gt;treatments&lt;/EM&gt;&lt;/STRONG&gt;.&amp;nbsp; The other three treatments are &lt;EM&gt;accept&lt;/EM&gt;, &lt;EM&gt;avoid&lt;/EM&gt;, or &lt;EM&gt;transfer&lt;/EM&gt;.&lt;/P&gt;</description>
    <pubDate>Thu, 01 Jun 2023 20:21:54 GMT</pubDate>
    <dc:creator>ericgeater</dc:creator>
    <dc:date>2023-06-01T20:21:54Z</dc:date>
    <item>
      <title>Risk Mitigation vs Risk Treatment</title>
      <link>https://community.isc2.org/t5/CGRC-Study-Group/Risk-Mitigation-vs-Risk-Treatment/m-p/59618#M66</link>
      <description>Hello all!&lt;BR /&gt;&lt;BR /&gt;I was hoping to get some input/clarification on the two terms I’ve seen some people use interchangeably, but I’m pretty sure they mean two different things.&lt;BR /&gt;&lt;BR /&gt;Risk Mitigation is putting controls in place to reduce or limit the adverse affects of risks, identified or likely to occur.&lt;BR /&gt;&lt;BR /&gt;Risk treatment is after the risk assessment, where you look at the identified risks and create controls to…treat them.&lt;BR /&gt;&lt;BR /&gt;So basically Mitigation is proactive approach that can basically be done anytime, while risk treatment is reactive, something that is done only during the risk assessment and after a risk has been identified.&lt;BR /&gt;&lt;BR /&gt;Thanks in advance!</description>
      <pubDate>Thu, 01 Jun 2023 14:05:56 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CGRC-Study-Group/Risk-Mitigation-vs-Risk-Treatment/m-p/59618#M66</guid>
      <dc:creator>JYeager</dc:creator>
      <dc:date>2023-06-01T14:05:56Z</dc:date>
    </item>
    <item>
      <title>Re: Risk Mitigation vs Risk Treatment</title>
      <link>https://community.isc2.org/t5/CGRC-Study-Group/Risk-Mitigation-vs-Risk-Treatment/m-p/59632#M67</link>
      <description>&lt;P&gt;I've always understood risk &lt;STRONG&gt;&lt;EM&gt;mitigation&lt;/EM&gt;&lt;/STRONG&gt;&amp;nbsp;to itself be one of the four risk &lt;STRONG&gt;&lt;EM&gt;treatments&lt;/EM&gt;&lt;/STRONG&gt;.&amp;nbsp; The other three treatments are &lt;EM&gt;accept&lt;/EM&gt;, &lt;EM&gt;avoid&lt;/EM&gt;, or &lt;EM&gt;transfer&lt;/EM&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2023 20:21:54 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CGRC-Study-Group/Risk-Mitigation-vs-Risk-Treatment/m-p/59632#M67</guid>
      <dc:creator>ericgeater</dc:creator>
      <dc:date>2023-06-01T20:21:54Z</dc:date>
    </item>
    <item>
      <title>Re: Risk Mitigation vs Risk Treatment</title>
      <link>https://community.isc2.org/t5/CGRC-Study-Group/Risk-Mitigation-vs-Risk-Treatment/m-p/59635#M68</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/136236425"&gt;@ericgeater&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;I've always understood risk &lt;STRONG&gt;&lt;EM&gt;mitigation&lt;/EM&gt;&lt;/STRONG&gt;&amp;nbsp;to itself be one of the four risk &lt;STRONG&gt;&lt;EM&gt;treatments&lt;/EM&gt;&lt;/STRONG&gt;.&amp;nbsp; The other three treatments are &lt;EM&gt;accept&lt;/EM&gt;, &lt;EM&gt;avoid&lt;/EM&gt;, or &lt;EM&gt;transfer&lt;/EM&gt;.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;That too is my understanding.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In some circles, I have seen claims that "ignoring" or "denying" are additional treatments, but truly those are just cases of implicitly accepting risk.&amp;nbsp; Read up on the &lt;A href="https://en.wikipedia.org/wiki/Space_Shuttle_Challenger_disaster" target="_blank"&gt;Challenger's demise&lt;/A&gt; as a great example of NASA management implicitly accepting risk by denying the engineers' assessment.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2023 23:49:18 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CGRC-Study-Group/Risk-Mitigation-vs-Risk-Treatment/m-p/59635#M68</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2023-06-01T23:49:18Z</dc:date>
    </item>
    <item>
      <title>Re: Risk Mitigation vs Risk Treatment</title>
      <link>https://community.isc2.org/t5/CGRC-Study-Group/Risk-Mitigation-vs-Risk-Treatment/m-p/59651#M69</link>
      <description>&lt;P&gt;For simplicity's sake, I chose to leave out "ignore" because it isn't part of the exam, nor the curriculum.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But yeah, "ignore" is a risk treatment, too.&amp;nbsp; A very, very stupid risk treatment.&amp;nbsp;&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_squinting_face:"&gt;😆&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2023 13:20:04 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CGRC-Study-Group/Risk-Mitigation-vs-Risk-Treatment/m-p/59651#M69</guid>
      <dc:creator>ericgeater</dc:creator>
      <dc:date>2023-06-02T13:20:04Z</dc:date>
    </item>
    <item>
      <title>Re: Risk Mitigation vs Risk Treatment</title>
      <link>https://community.isc2.org/t5/CGRC-Study-Group/Risk-Mitigation-vs-Risk-Treatment/m-p/59667#M71</link>
      <description>Ty everyone!! I appreciate the answers and it helps me understand it now!</description>
      <pubDate>Sat, 03 Jun 2023 14:07:50 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CGRC-Study-Group/Risk-Mitigation-vs-Risk-Treatment/m-p/59667#M71</guid>
      <dc:creator>JYeager</dc:creator>
      <dc:date>2023-06-03T14:07:50Z</dc:date>
    </item>
  </channel>
</rss>

