High School AdvancedA15.10Risk Management and Compliance

Lesson A15.10

Risk Decision Lab

This capstone combines everything in A15. You will move from business context and risk analysis through controls, evidence, compliance, exceptions, suppliers, prioritization, and leadership communication to a final set of enterprise risk decisions.

Every organization, service, supplier, control, exception, evidence record, and leadership decision is fictional. The lab requires no scanning, exploitation, credential access, or testing of real systems.

Lesson Progress

Risk Decision Lab

High School AdvancedA15: Risk Management and Compliance • Lesson 10 of 10

100% complete

Readiness Check

A15.10 Entry Readiness

0/4 ready

Capstone Mission

Build One Decision Package From Many Kinds of Evidence

Real risk decisions rarely arrive as one perfect record. The business owner may know the consequence. The control owner may know the safeguard. Governance may know the requirement. Audit may know the evidence quality. Vendor management may know the supplier. The security leader must connect those perspectives into one coherent recommendation.

The capstone goal is not to produce the most risk records. It is to produce the clearest defensible decisions.

Learning Objectives

Five Capabilities for the Final A15 Lab

1

Integrate asset, threat, impact, likelihood, ownership, control, compliance, evidence, exception, supplier, and leadership information into one coherent risk decision package.

2

Resolve conflicting evidence, ownership gaps, expired approvals, control weaknesses, supplier dependencies, and residual-risk questions without hiding uncertainty.

3

Prioritize enterprise risks using business impact, likelihood, control effectiveness, evidence confidence, dependency, time sensitivity, and risk tolerance.

4

Produce defensible treatment, acceptance, monitoring, escalation, blocking, and closure decisions with owners, milestones, evidence, and review triggers.

5

Complete an Enterprise Risk Decision Package that serves as the final A15 Risk Register and Leadership Recommendation portfolio artifact.

Integrated Review

Nine Domains of an Enterprise Risk Decision

Business context

Identify the service, data, people, supplier, operational objective, and business dependency behind the risk.

Decision question: What business outcome could be harmed, and how important is it?

Evidence: Service inventory, data classification, dependency map, business-owner record.

Risk scenario

Connect the asset, threat event, exposure condition, consequence, current controls, and uncertainty.

Decision question: What could happen, why is it plausible, and what would the organization lose?

Evidence: Risk analysis worksheet, control findings, incident or outage summaries, architecture records.

Ownership

Separate risk owner, control owner, remediation owner, evidence owner, supplier sponsor, and approval authority.

Decision question: Who owns the consequence, who operates the safeguard, and who must act next?

Evidence: Risk register, ownership register, governance records, supplier sponsorship.

Control effectiveness

Evaluate design, operation, coverage, evidence, exceptions, and compensating controls.

Decision question: Do the controls reduce the intended risk across the intended scope?

Evidence: Control tests, operational records, configuration reviews, recovery exercises.

Compliance and governance

Evaluate applicable requirements, mappings, exceptions, evidence, and status.

Decision question: Which requirements are Met, Partially Met, Compensating, Unknown, or Not Met?

Evidence: Framework mapping register, policies, standards, exception records.

Evidence confidence

Evaluate relevance, sufficiency, reliability, freshness, attribution, completeness, and contradictions.

Decision question: How confident should decision makers be in the current conclusion?

Evidence: Audit evidence register, workpapers, test records, current source records.

Third-party dependency

Evaluate supplier criticality, assurance, concentration, fourth parties, continuity, and exit.

Decision question: What risk remains because the organization depends on a service it does not fully control?

Evidence: Supplier review, contract, continuity plan, architecture dependency map, assurance records.

Decision and treatment

Compare Treat, Accept, Avoid, Transfer/Share, Monitor, Conditional, Blocked, and Closed options.

Decision question: Which option best balances risk reduction, business need, cost, effort, timing, and tolerance?

Evidence: Risk brief, treatment plan, acceptance record, budget/effort estimate, leadership decision.

Leadership communication

Translate the technical record into a concise business decision.

Decision question: What should leadership decide, who owns it, when must it happen, and what residual risk remains?

Evidence: Leadership risk brief, dashboard, decision history, milestone plan.

Decision States

Choose the State That Matches Current Evidence and Authority

Treat

Active risk reduction is required because current residual risk is above tolerance or controls are not strong enough.

Evidence needed: Clear remediation owner, milestones, expected control outcome, and closure evidence.

Example: Legacy trust and ownership gaps remain High residual risk.

Monitor

Current residual risk is acceptable under current controls, but the risk remains business-relevant.

Evidence needed: Current control evidence, owner, review cadence, and change triggers.

Example: Recovery controls are strong and regularly validated, with normal residual uncertainty.

Conditional

Activity may continue only while specific bounded conditions remain true.

Evidence needed: Explicit conditions, expiry/review date, owner, evidence, and trigger that changes the state.

Example: Partner certificate renewal must complete before the current certificate expires.

Accepted Risk

An authorized owner formally accepts known residual risk for a defined scope and period.

Evidence needed: Current risk evidence, rationale, authority, scope, review trigger, and residual-risk statement.

Example: Moderate recovery uncertainty remains after successful testing and is accepted until the next annual validation.

Blocked

Current risk, missing authority, failed control, or evidence uncertainty prevents approval.

Evidence needed: Clear blocker, owner, evidence gap, and condition for reconsideration.

Example: An expired exception cannot support continued operation without current evidence and reapproval.

Closed

Evidence shows the risk was removed, retired, avoided, or reduced to the approved target state.

Evidence needed: Objective closure evidence and updated related risk/control/compliance records.

Example: Obsolete trust is removed and preferred controls are validated.

Prioritization

Priority Is More Than Impact × Likelihood

Business impact

How severe is the consequence to operations, data, people, finances, legal obligations, or trust?

Higher-priority signal: Critical service outage, sensitive data consequence, major operational disruption, significant compliance or trust impact.

Likelihood

How plausible is the scenario under current exposure, controls, history, change, and dependency?

Higher-priority signal: Multiple active gaps, weak controls, recurring issues, unstable dependency, or strong evidence of occurrence.

Control effectiveness

How much do current controls actually reduce the risk?

Higher-priority signal: Design or operation is Partially Effective, Ineffective, Unknown, or coverage is materially incomplete.

Evidence confidence

How trustworthy is the evidence behind the current conclusion?

Higher-priority signal: Stale, partial, missing, contradictory, or weakly attributed evidence.

Dependency / concentration

How much does the organization depend on one system, supplier, platform, team, or trust relationship?

Higher-priority signal: No practical alternative, shared critical dependency, or difficult recovery path.

Time sensitivity

Is there an expiry, launch, renewal, migration, audit, contract, or operational deadline?

Higher-priority signal: Exception expiry, certificate expiry, contract renewal, overdue P0 work, or imminent business event.

Risk tolerance

Is the residual risk within the authority and tolerance of the current decision maker?

Higher-priority signal: Residual risk exceeds approved tolerance or requires higher approval authority.

Ownership

Is there a current accountable risk owner and assigned remediation/control ownership?

Higher-priority signal: Unowned risk, missing approver, ambiguous business sponsor, or unresolved handoff.

Evidence Confidence

Decision Strength Should Match Evidence Strength

Decision-ready

Current, direct, attributable, sufficiently complete evidence supports the conclusion and scope.

Decision use: Supports Treat, Monitor, Accepted Risk, Conditional, or Closed decisions with strong confidence.

Decision-ready with caveat

Evidence supports the decision, but a bounded limitation remains visible.

Decision use: Supports a decision when the limitation is understood and monitored.

Partial

Some but not all intended scope or evidence elements are supported.

Decision use: Often supports Conditional or Treat rather than full approval.

Stale

Evidence may no longer represent the current environment or control state.

Decision use: Triggers refresh before relying on the old conclusion.

Contradictory

Two or more credible sources support different conclusions.

Decision use: Requires reconciliation; preserve the conflict rather than forcing certainty.

Missing

Required evidence cannot currently be produced.

Decision use: Creates Unknown confidence and may justify Blocked or Conditional status.

Enterprise Evidence

Eight Integrated Northbridge Risk Decisions

DEC-801TreatP0

Legacy Reporting Modernization

Linked records: RSK-102 / CTL-202 / MAP-302 / AUD-402 / EXC-501 / LDR-701

Business context

Historical reporting remains required for ongoing business and governance operations.

Risk scenario

Legacy trust, ownership, and transport gaps could expose sensitive reports or interrupt service.

Impact

High

Likelihood

Medium-High

Controls

Restricted network scope, partial monitoring, modernization program, monthly governance review

Control state

Compensating / Partially Effective

Compliance

Compensating — preferred legacy control state not fully met

Evidence

Current exception and network evidence; partial dependency inventory; active treatment milestones

Confidence

Moderate

Risk owner

Reporting Product Owner

Supplier / dependency

No material external supplier dependency drives the core risk

Exception

EXC-501 approved through 2027-01-31

Treatment options

Continue P0 treatment; accelerate retirement; reduce service scope; seek higher-authority acceptance

Recommendation

Continue P0 treatment and escalate any missed milestone. Do not convert the remaining High residual risk to Accepted Risk without higher authority and updated evidence.

Residual risk

High

Change trigger

Missed P0 milestone, exception expiry, incident, owner change, new sensitive data

Closure criteria

Modernization complete, obsolete trust removed, ownership current, protected transport validated

DEC-802TreatP1

Shared External Identity Concentration

Linked records: RSK-105-related dependency / TPR-602 / LDR-702

Business context

Several critical applications depend on one external identity platform.

Risk scenario

A major identity-provider outage could simultaneously interrupt access to multiple critical services.

Impact

High

Likelihood

Medium

Controls

Current supplier assurance, service monitoring, limited emergency-access path, recovery procedure

Control state

Partially Effective for continuity

Compliance

No direct compliance gap; business concentration remains

Evidence

Current assurance, uptime history, dependency map, limited alternate-access procedure

Confidence

High for dependency; Moderate for extreme-outage conditions

Risk owner

Identity Platform Owner

Supplier / dependency

Critical external identity provider with High concentration

Exception

No exception

Treatment options

Improve continuity; accept concentration; redesign dependency; transition provider

Recommendation

Fund alternate-access and continuity improvements while retaining the current provider.

Residual risk

Moderate-High

Change trigger

Supplier incident, architecture expansion, continuity-test failure, acquisition or service change

Closure criteria

Residual concentration reduced to tolerance and alternate-access capability validated

DEC-803ConditionalP1 time-sensitive

Partner Scheduling Certificate Renewal

Linked records: RSK-103 / CTL-203 / MAP-303 / AUD-403 / EXC-502 / TPR-603 / LDR-703

Business context

Scheduling operations depend on a trusted partner integration.

Risk scenario

Certificate lifecycle delay could interrupt the integration when the current trust credential expires.

Impact

Medium-High

Likelihood

Medium

Controls

Daily expiry monitoring, renewal workflow, sponsor oversight, protected transport

Control state

Partially Effective until replacement validation completes

Compliance

Partially Met

Evidence

Current certificate, alert, renewal ticket, sponsor confirmation

Confidence

High

Risk owner

Integration Owner

Supplier / dependency

Partner scheduling service; Low-Medium concentration

Exception

EXC-502 Conditional acceptance during renewal window

Treatment options

Complete renewal; accelerate validation; pause integration; accept limited short-term residual risk

Recommendation

Keep Conditional and complete replacement validation before expiry.

Residual risk

Moderate

Change trigger

Renewal delay, partner ownership change, certificate status change

Closure criteria

Replacement validated and old trust retired

DEC-804TreatP1

Critical Payroll Supplier Continuity

Linked records: TPR-604 / LDR-704 / RSK-105-pattern

Business context

Payroll is a critical employee service with no practical short-term substitute.

Risk scenario

A major provider outage could delay payroll processing and require emergency manual procedures.

Impact

High

Likelihood

Medium

Controls

Supplier monitoring, current assurance, contract commitments, continuity plan, limited emergency payroll procedure

Control state

Partially Effective for continuity

Compliance

Partially Met for continuity expectations

Evidence

Current supplier assurance, contract, continuity plan, limited emergency-procedure evidence

Confidence

Moderate-High

Risk owner

Finance Operations Owner

Supplier / dependency

Critical payroll SaaS with High concentration and low substitutability

Exception

Temporary acceptance may be considered only with authorized approval

Treatment options

Improve continuity; accept residual concentration; change provider; build stronger internal emergency capability

Recommendation

Approve continuity improvement and validate emergency payroll operations before contract renewal.

Residual risk

Moderate-High

Change trigger

Supplier incident, missed continuity milestone, contract change, material service change

Closure criteria

Continuity capability reaches target and residual concentration is within approved tolerance

DEC-805BlockedP1 evidence gap

Temporary Workspace Destruction Evidence

Linked records: RSK-107 / CTL-207 / MAP-306 / AUD-406 / AUD-407 / EXC-505 / LDR-705

Business context

Temporary data-science workspaces may contain sensitive derived data.

Risk scenario

Sensitive data could persist beyond approved project closure.

Impact

Medium-High

Likelihood

Low-Medium

Controls

Encrypted storage, restricted access, automated lifecycle processing

Control state

Design Effective; operating state Unknown

Compliance

Partially Met

Evidence

Partial cleanup logs plus contradictory owner attestation

Confidence

Low-Moderate

Risk owner

Data Science Platform Owner

Supplier / dependency

No material supplier dependency in this risk decision

Exception

EXC-505 Under Review; not approved

Treatment options

Refresh evidence; pause sensitive new projects; strengthen lifecycle monitoring; seek conditional approval

Recommendation

Do not approve risk acceptance yet. Reconcile the inventory, cleanup logs, and owner attestation across the full population.

Residual risk

Moderate and uncertain

Change trigger

Evidence reconciliation complete, cleanup failure, data-classification change, new sensitive project

Closure criteria

Full-population destruction evidence confirms expected lifecycle operation

DEC-806MonitorP2

Critical Recovery Capability

Linked records: RSK-104 / CTL-204 / MAP-304 / AUD-404 / EXC-503 / LDR-706

Business context

Critical services depend on reliable backup restoration after major disruption.

Risk scenario

A real recovery event could differ from planned testing and delay restoration.

Impact

High

Likelihood

Low-Medium

Controls

Encrypted backups, protected replication, restricted recovery, current restore testing

Control state

Effective

Compliance

Met

Evidence

Current restore test, key-version mapping, issue closure, current owners

Confidence

High

Risk owner

Resilience Leader

Supplier / dependency

Provider dependency monitored but not currently a blocking condition

Exception

EXC-503 approved residual-risk acceptance

Treatment options

Monitor; increase test frequency; redesign recovery; accept normal residual uncertainty

Recommendation

Maintain Monitor / Accepted Risk with annual full validation and change-triggered reassessment.

Residual risk

Moderate normal recovery uncertainty

Change trigger

Restore failure, platform migration, key-lifecycle change, provider change

Closure criteria

Not intended for closure while critical recovery dependency exists; revalidate acceptance

DEC-807BlockedP0 governance

Expired Legacy Transfer Approval

Linked records: EXC-507 / LDR-707

Business context

It is unclear whether a former legacy transfer workflow remains active.

Risk scenario

The organization could be relying on an expired approval and stale controls.

Impact

Potentially High

Likelihood

Unknown

Controls

Former restricted partner list and monitoring; current state unverified

Control state

Unknown

Compliance

Unknown / previous exception expired

Evidence

Expired exception, stale control evidence, no current workflow confirmation

Confidence

Low

Risk owner

Legacy Integration Owner

Supplier / dependency

Potential external transfer partner relationship requires current confirmation

Exception

EXC-507 Expired

Treatment options

Confirm retirement; reassess and reapprove; remediate; block continued use

Recommendation

Treat the old approval as invalid. Confirm workflow status immediately and block continued reliance if still active without a fresh decision.

Residual risk

Unknown

Change trigger

Current workflow evidence obtained

Closure criteria

Workflow retirement proven or fresh authorized governance decision completed

DEC-808MonitorP3

Analytics Export Temporary Storage

Linked records: RSK-106 / CTL-206 / MAP-306-related / AUD-406-related

Business context

Approved analytics exports support reporting while creating temporary copies of sensitive data.

Risk scenario

Temporary export packages could remain in staging longer than intended.

Impact

Medium-High

Likelihood

Low-Medium

Controls

Export approval, encrypted staging, short retention, automated cleanup, exception monitoring

Control state

Effective

Compliance

Met for export-staging scope

Evidence

Current lifecycle policy, cleanup logs, exception queue

Confidence

High

Risk owner

Analytics Product Owner

Supplier / dependency

Approved export recipient reviewed separately under TPR-606

Exception

No active exception

Treatment options

Monitor; reduce retention further; redesign staging; discontinue exports

Recommendation

Monitor under current controls and revalidate after export-process or recipient changes.

Residual risk

Low-Moderate

Change trigger

New recipient, new data class, retention change, export redesign, cleanup failure

Closure criteria

Not intended for closure while workflow remains active; monitor lifecycle evidence

Fake Dashboard

Northbridge Enterprise Risk Decision Dashboard

Fictional priority, treatment, evidence confidence, and governance summary

Decision records

8

Integrated business, control, compliance, evidence, exception, supplier, and leadership records

P0 decisions

2

Legacy reporting treatment and expired legacy transfer governance

Blocked

2

Workspace evidence contradiction and expired legacy transfer approval

Treat / Conditional

4

Legacy, identity concentration, partner renewal, and payroll continuity require active action

Fake SOC Alert

Two P0 Decisions Require Immediate Governance Attention

Source: Fictional Enterprise Risk Decision Review • Time: 10:54

High Severity
DEC-801 remains High residual risk under compensating controls, while DEC-807 relies on an expired approval with Low evidence confidence. Both require active leadership attention for different reasons.
Defensive recommendation: Keep DEC-801 in P0 treatment with milestone escalation. Keep DEC-807 Blocked until current workflow evidence and a fresh governance decision exist.

Evidence Conflicts

Five Conflicts the Decision Package Must Preserve and Resolve

CONFLICT-01

Owner attestation vs. operating evidence

Conflicting sources: Workspace owner says cleanup is complete; full-population cleanup evidence is incomplete.

Decision risk: The organization could approve acceptance based on an assertion that is not fully supported.

Resolution: Keep confidence Low-Moderate, preserve contradiction, reconcile inventory and lifecycle logs before approval.

CONFLICT-02

Supplier assurance vs. concentration

Conflicting sources: Identity supplier assurance is strong; multiple critical services still share one dependency.

Decision risk: Leadership could confuse strong supplier controls with low business dependency risk.

Resolution: Keep supplier-control confidence High while treating concentration separately.

CONFLICT-03

Approved exception vs. unmet preferred control

Conflicting sources: Legacy exception is approved; preferred modernization controls are incomplete.

Decision risk: The organization could report the requirement as fully Met when it is only Compensating.

Resolution: Keep compliance state Compensating and residual risk High until closure evidence exists.

CONFLICT-04

Expired approval vs. historical legitimacy

Conflicting sources: Legacy transfer was previously approved; the approval has expired.

Decision risk: Teams could continue relying on old authorization after its governance boundary ended.

Resolution: Treat old approval as invalid and require current evidence plus a fresh decision.

CONFLICT-05

Strong recovery test vs. unavoidable uncertainty

Conflicting sources: Current recovery evidence is strong; real disaster conditions can still differ from planned testing.

Decision risk: Teams could either overstate certainty or undervalue strong controls.

Resolution: Maintain High confidence in current control effectiveness while accepting bounded residual uncertainty.

Remediation Board

Eight Actions That Change the Enterprise Risk State

REM-801P0

Confirm whether the expired legacy transfer workflow is still active.

Owner / due

Legacy Integration OwnerImmediate

Evidence / effect

Evidence: Current workflow inventory + owner confirmation + control state

Decision effect: Moves DEC-807 from Blocked to Closed if retired, or to reassessed Treat/Conditional if active.

REM-802P0

Keep legacy reporting modernization milestones on schedule and escalate slippage.

Owner / due

Reporting Product OwnerMonthly

Evidence / effect

Evidence: Milestone completion + preferred-control validation

Decision effect: Reduces DEC-801 residual risk and supports eventual closure of EXC-501.

REM-803P1

Reconcile temporary-workspace inventory, cleanup logs, and owner attestation.

Owner / due

Data Science Platform OwnerBefore next sensitive project closeout

Evidence / effect

Evidence: Full-population lifecycle validation

Decision effect: Allows DEC-805 to move from Blocked to Monitor/Conditional if evidence supports operation.

REM-804P1

Complete partner certificate replacement validation and retire old trust.

Owner / due

Integration OwnerBefore certificate expiration

Evidence / effect

Evidence: Replacement validation + old-trust retirement record

Decision effect: Moves DEC-803 from Conditional to Monitor/Closed treatment state.

REM-805P1

Improve alternate-access and continuity for the shared identity provider.

Owner / due

Identity Platform OwnerDesign this quarter; validate next quarter

Evidence / effect

Evidence: Continuity design + safe validation + leadership acceptance of residual concentration

Decision effect: Reduces DEC-802 concentration risk.

REM-806P1

Validate emergency payroll operating procedure before supplier contract renewal.

Owner / due

Finance Operations OwnerBefore renewal

Evidence / effect

Evidence: Safe continuity exercise + updated plan + issue closure

Decision effect: Reduces DEC-804 residual continuity risk.

REM-807P2

Maintain annual full recovery validation and event-driven reassessment.

Owner / due

Resilience LeaderAnnual + trigger based

Evidence / effect

Evidence: Current restore test + dependency map + issue closure

Decision effect: Maintains DEC-806 accepted residual risk within approved tolerance.

REM-808P3

Continue analytics export cleanup monitoring and recipient review.

Owner / due

Analytics Product OwnerMonthly + annual recipient review

Evidence / effect

Evidence: Cleanup monitoring + recipient approval + retention evidence

Decision effect: Maintains DEC-808 at Low-Moderate residual risk.

Decision Board

What Leadership Should Decide

DEC-801 Legacy Reporting

Current state: Treat

Leadership decision: Continue P0 modernization; escalate missed milestones

Rationale: High residual risk and compensating controls remain.

DEC-802 Identity Concentration

Current state: Treat

Leadership decision: Fund continuity and alternate-access improvement

Rationale: Strong supplier assurance does not eliminate shared critical dependency.

DEC-803 Partner Certificate

Current state: Conditional

Leadership decision: Complete renewal before expiry

Rationale: Time-sensitive but currently controlled lifecycle risk.

DEC-804 Payroll Supplier

Current state: Treat

Leadership decision: Approve continuity improvement before renewal

Rationale: Critical service with limited substitutability.

DEC-805 Workspace Cleanup

Current state: Blocked

Leadership decision: Do not accept until evidence contradiction is resolved

Rationale: Operating effectiveness and residual risk are not sufficiently proven.

DEC-806 Recovery

Current state: Monitor / Accepted Risk

Leadership decision: Maintain current validation cadence

Rationale: Strong controls with bounded normal recovery uncertainty.

DEC-807 Legacy Transfer

Current state: Blocked

Leadership decision: Treat old approval as invalid until current state is known

Rationale: Expired governance and Low evidence confidence.

DEC-808 Analytics Export

Current state: Monitor

Leadership decision: Maintain lifecycle evidence and review triggers

Rationale: Current controls are Effective with Low-Moderate residual risk.

Fake Log Panel

Fictional Enterprise Risk Decision Log

training-log-viewer.log
[08:30] DEC-801 state=TREAT priority=P0 residual=HIGH confidence=MODERATE
[08:54] DEC-802 state=TREAT priority=P1 concentration=HIGH confidence=HIGH_DEPENDENCY
[09:18] DEC-803 state=CONDITIONAL priority=P1 cert_renewal=OPEN
[09:42] DEC-804 state=TREAT priority=P1 payroll_continuity=PARTIAL
[10:06] DEC-805 state=BLOCKED priority=P1 evidence=CONTRADICTORY
[10:30] DEC-806 state=MONITOR_ACCEPTED priority=P2 evidence=STRONG
[10:54] DEC-807 state=BLOCKED priority=P0 exception=EXPIRED confidence=LOW
[11:18] DEC-808 state=MONITOR priority=P3 control=EFFECTIVE

Training note: this is fake data for defensive analysis practice only.

Analyze the Evidence

Evidence Analysis: Workspace Decision

Temporary workspace design includes encryption, restricted access, and automated cleanup.
Operating cleanup evidence is incomplete across the full population.
A control-owner attestation says cleanup is complete.
The full inventory has not yet been reconciled against the logs.
The exception request is still Under Review.

What is the strongest current decision for DEC-805?

Common Decision Mistakes

Eight Ways Enterprise Risk Decisions Become Unreliable

1

Choose a state before reviewing evidence

Why it fails: The team decides it wants to Accept or Close the risk and then looks for evidence that supports that outcome.

Better approach: Review business context, controls, evidence, uncertainty, and authority before choosing the state.

2

Use one score as the final decision

Why it fails: A risk number replaces ownership, evidence, dependency, timing, and treatment analysis.

Better approach: Use scores only as summaries inside a richer decision record.

3

Close because a remediation ticket completed

Why it fails: Project completion is treated as proof that residual risk reached the target state.

Better approach: Require objective control or architecture validation.

4

Accept because treatment is inconvenient

Why it fails: The organization substitutes acceptance for feasible remediation.

Better approach: Compare options and confirm the residual risk is actually within authorized tolerance.

5

Ignore conflicting evidence

Why it fails: One convenient source is chosen and the contradictory source disappears from the record.

Better approach: Preserve both sources and resolve what each proves.

6

Treat compliance status as the whole risk decision

Why it fails: A Met requirement is assumed to mean business risk is acceptable.

Better approach: Evaluate actual residual business risk separately.

7

Supplier owns the consequence

Why it fails: The organization assumes strong contract or assurance evidence transfers accountability.

Better approach: Keep the internal risk owner accountable for business impact.

8

Leadership brief hides uncertainty

Why it fails: Low-confidence evidence is summarized as a certain conclusion.

Better approach: State confidence and the next evidence needed.

Scenario Decision Lab

Scenario Decision Lab 1 — Contradictory Workspace Evidence

The temporary-workspace control is well designed, but full-population cleanup evidence is incomplete and conflicts with a current owner attestation.

Scenario Decision Lab

Scenario Decision Lab 2 — Expired Governance and Unknown Current State

A legacy transfer exception expired, control evidence is stale, and nobody has confirmed whether the workflow is still active.

Capstone Lab

Build the Enterprise Risk Decision Package

Combine your A15 portfolio artifacts into one fictional enterprise package. The package should show not just the risk data, but how the organization reaches, documents, and communicates decisions.

1

Create an executive overview of the fictional organization and its critical services.

2

Include at least twenty-five RSK records from your Cybersecurity Risk Register.

3

Include at least twenty-five CTL records from your Control Effectiveness Review.

4

Include at least twenty-five MAP records from your Framework and Control Mapping Register.

5

Include at least thirty AUD records from your Audit Evidence Register.

6

Include at least twenty-five EXC records from your Risk Acceptance and Exception Register.

7

Include at least twenty-five TPR records from your Third-Party Risk Review.

8

Include at least fifteen LDR leadership briefs.

9

Create at least ten final DEC decision records.

10

Link each DEC record to relevant RSK, CTL, MAP, AUD, EXC, TPR, and LDR records.

11

State the affected business service.

12

State the risk scenario.

13

State impact and likelihood.

14

State control effectiveness.

15

State compliance status.

16

State evidence confidence.

17

State risk owner.

18

State control and remediation owners.

19

State supplier or concentration dependency where relevant.

20

State active exception or acceptance where relevant.

21

Compare at least two treatment options.

22

Choose a final decision state.

23

Assign a priority.

24

State residual risk.

25

State the leadership recommendation.

26

Set a milestone or due date.

27

Define escalation criteria.

28

Define review triggers.

29

Define closure criteria.

30

Include at least two P0 risks.

31

Include at least three Treat decisions.

32

Include at least two Monitor decisions.

33

Include at least two Conditional decisions.

34

Include at least two Accepted Risk decisions.

35

Include at least two Blocked decisions.

36

Include at least two Closed decisions with objective closure evidence.

37

Include at least three supplier or concentration risks.

38

Include at least three evidence conflicts.

39

Include at least three expired or near-expiry governance decisions.

40

Include at least three cases where compliance status and residual business risk differ.

41

Build one leadership dashboard summarizing priority, decision state, evidence confidence, overdue treatment, expired exceptions, and concentration risk.

42

Write a final leadership recommendation explaining the top five actions for the next review period.

Capstone safety boundary

Use fictional organizations, services, suppliers, controls, evidence, owners, contracts, risks, and decisions only. Do not scan, probe, exploit, bypass, enumerate, test, or access real systems, vendors, accounts, credentials, or confidential organizational records.

Analyze the Evidence

Evidence Analysis: Expired Legacy Transfer Governance

The previous exception expired.
Current control evidence is stale.
The organization has not confirmed whether the workflow is retired.
The historical approval was limited to a temporary migration period.
No fresh acceptance or exception has been approved.

What is the strongest decision for DEC-807?

Advanced Challenge

Design an Enterprise Risk Governance Standard

Create a fictional standard that defines how the organization moves from risk identification to evidence, treatment, leadership decision, monitoring, escalation, acceptance, and closure.

1

Risk ID and decision ID standards

2

Business-context requirements

3

Impact and likelihood method

4

Ownership model

5

Control mapping

6

Control-test expectations

7

Compliance mapping

8

Evidence-quality standards

9

Exception governance

10

Supplier-risk integration

11

Concentration-risk analysis

12

Risk-tolerance boundaries

13

Decision-state definitions

14

Priority model

15

Escalation rules

16

Leadership-brief standard

17

Review cadence

18

Change triggers

19

Closure evidence

20

Decision-history retention

The strongest standard should make risk decisions repeatable without pretending that every judgment can be reduced to a rigid formula.

Defender Habits

A15.10 Defender Checklist

Skill Check

Seven Questions

Check Your Understanding

A15.10 Mini Quiz: Risk Decision Lab

Choose your answers first. Explanations appear only after submission.

1. What is the strongest basis for an enterprise risk decision?

2. What should happen when credible evidence sources contradict each other?

3. When is Blocked an appropriate risk state?

4. What is strongest for an Accepted Risk decision?

5. Why should supplier assurance and concentration risk be analyzed separately?

6. What proves a risk can be Closed?

7. What should a leadership recommendation include?

Portfolio Prompt

Final Portfolio Build — Enterprise Risk Decision Package

Complete the final A15 Risk Register and Leadership Recommendation as an Enterprise Risk Decision Package. Integrate your Risk Analysis Worksheet, Cybersecurity Risk Register, Control Effectiveness Review, Framework and Control Mapping Register, Audit Evidence Register, Risk Acceptance and Exception Register, Third-Party Risk Review, Leadership Risk Brief, remediation board, decision board, and at least ten final DEC records. Every major decision should show business context, evidence confidence, ownership, control state, compliance state, residual risk, treatment options, priority, recommendation, milestone, escalation, review triggers, and closure criteria.

Preserve uncertainty instead of hiding it.
Link decisions across A15 artifacts.
Separate supplier assurance from business dependency.
Treat expired approvals as expired.
Use objective closure evidence.
Use fictional provider-neutral records only.

Confidence / Readiness Reflection

Are You Ready for the A15 Module Test?

The module test checks whether you can reason across the full A15 lifecycle. You should be able to explain why a decision is Treat, Monitor, Conditional, Accepted Risk, Blocked, or Closed using business context, controls, evidence, governance, and ownership.

1

I can integrate risk, control, compliance, evidence, exception, supplier, and leadership records.

2

I can preserve and resolve contradictory evidence.

3

I can choose a decision state that matches residual risk and authority.

4

I can prioritize enterprise risks using more than a single score.

5

I can produce a concise leadership recommendation with owner, timeline, residual risk, and review triggers.

Portfolio Build Guide

How to Make the Enterprise Risk Decision Package Look Professional

Use linked records

A final DEC record should trace back to the risk, controls, compliance mappings, evidence, exception, supplier, and leadership brief that support it.

Show evidence confidence

A decision should say whether evidence is strong, caveated, partial, stale, contradictory, or missing.

Show ownership

Risk owner, control owner, remediation owner, supplier sponsor, and approver should be distinct where responsibility differs.

Show priority logic

Explain urgency using impact, likelihood, controls, evidence, dependency, timing, and tolerance.

Show treatment tradeoffs

Compare realistic options instead of presenting one unexplained answer.

Show residual risk

Explain what remains after the recommended action and whether it is within tolerance.

Use evidence-based closure

Close a risk only when objective evidence proves the approved target state exists.

Prepare for the module test

Review the decision states, ownership model, control/evidence logic, exceptions, supplier dependency, and leadership communication before continuing.

Key Takeaways

What You Should Remember

1.Enterprise risk decisions require business, technical, governance, supplier, evidence, and ownership context.
2.Risk scores help prioritize but should never replace reasoning.
3.Contradictory evidence should reduce confidence until reconciled.
4.Expired approvals cannot be treated as current governance.
5.A strong supplier can still create high concentration risk.
6.Accepted Risk must remain visible, owned, evidenced, and reviewable.
7.Blocked is appropriate when evidence, authority, or control state does not support approval.
8.Closure requires objective target-state evidence.
9.Leadership recommendations should state the decision, owner, timeline, residual risk, and change triggers.
10.The Enterprise Risk Decision Package completes the A15 portfolio and prepares you for the A15 Module Test.

Lesson Safety Boundary

Enterprise risk analysis uses safe, authorized, fictional evidence

Do not scan, probe, exploit, bypass, enumerate, test, or access real systems, vendors, accounts, credentials, or confidential organizational records. All risks, services, suppliers, controls, evidence, approvals, and leadership decisions in this lab are fictional.

Lesson Complete

A15.10 Risk Decision Lab Complete

You have completed the A15 lesson sequence and assembled the final Enterprise Risk Decision Package: risk analysis, risk register, controls, compliance mappings, audit evidence, exceptions, third-party risk, leadership briefs, remediation priorities, and final decision records. Next is the A15 Module Test.