High School IntermediateModule I14Lesson 4 of 8

I14.4 Risk Treatment and Control Selection

Learn how defenders compare fictional avoidance, reduction, transfer, acceptance, and monitoring while selecting controls that are proportionate, evidence-based, business-aware, testable, sustainable, and owned.

Lesson Progress

Risk Treatment and Control Selection

High School IntermediateI14: Security Policies and Risk • Lesson 4 of 8

50% complete

Readiness Check

Before You Start

0/5 ready

Professional Hook

The Strongest Control Is Not Always the Safest Control

The fictional Northbridge team wants to remove broad supplier, privileged, network, and storage access immediately. Some actions are clearly necessary, but an earlier least-privilege change broke an approved export workflow because a hidden dependency was not mapped. Strong risk treatment balances risk reduction with business need, evidence, dependencies, authority, staged validation, rollback, monitoring, recovery, sustainability, and residual risk.

Weak treatment

Choose the strictest control, deploy it globally, assume the ticket proves success, ignore dependencies, and close the risk without reviewing what remains.

Professional treatment

Compare options, define control objectives, assign owners, stage implementation, validate approved and denied behavior, preserve rollback, monitor, and obtain residual-risk approval.

Objective 1

Explain how fictional risk treatment connects avoidance, reduction, transfer, acceptance, monitoring, control selection, ownership, cost, feasibility, residual risk, and review.

Objective 2

Distinguish fictional preventive, detective, corrective, recovery, deterrent, governance, physical, administrative, technical, and compensating controls.

Objective 3

Compare fictional control options using risk reduction, business fit, evidence quality, dependency impact, implementation effort, operating cost, validation, and sustainability.

Objective 4

Build a fictional treatment plan with owners, approvals, sequence, deadlines, validation, rollback, monitoring, residual-risk decisions, and closure evidence.

Objective 5

Create a portfolio-safe fictional risk-treatment package with a treatment matrix, control rationale, control map, implementation plan, exceptions, findings, and leadership communication.

Why This Matters

Treatment Decisions Determine Which Risks Are Changed, Retained, Shared, Watched, or Removed

Fictional organizations have limited time, funding, staff, tools, and authority. They must choose controls that reduce practical risk without creating a larger service, privacy, accessibility, recovery, supplier, or operational problem. A treatment plan is defensible only when the organization can explain why the option was selected, how it will work, how it will be tested, what it costs, who owns it, and what risk remains.

Core Concept

Use the Scenario–Option–Control–Assurance Model

Scenario

Which fictional asset, threat, vulnerability, exposure, control condition, likelihood, impact, confidence, and owner define the risk?

Option

Should the fictional risk be avoided, reduced, transferred, accepted, monitored, or treated through a combination?

Control

Which fictional preventive, detective, corrective, recovery, governance, administrative, technical, physical, or compensating safeguards fit?

Assurance

Which fictional evidence, validation, rollback, monitoring, metrics, residual-risk decision, review, and closure prove the treatment works?

Key Vocabulary

Risk Treatment, Controls, and Assurance Terms

Risk treatment

A fictional decision to avoid, reduce, transfer, accept, or monitor a risk using approved controls, ownership, evidence, funding, validation, and review.

Risk avoidance

A fictional decision to stop, remove, or not begin an activity when the risk exceeds acceptable business value or cannot be controlled adequately.

Risk reduction

A fictional decision to lower likelihood, impact, exposure, or uncertainty through one or more controls.

Risk transfer

A fictional decision to move part of the financial, operational, contractual, or service consequence to another party while retaining accountability for remaining risk.

Risk acceptance

A fictional authorized decision to retain residual risk for a defined scope, reason, period, owner, and review condition.

Risk monitoring

A fictional decision to observe a risk, control, dependency, indicator, or environmental change before or alongside another treatment.

Preventive control

A fictional safeguard intended to stop or reduce the chance of an unwanted event before it occurs.

Detective control

A fictional safeguard intended to identify an event, control failure, drift, or suspicious condition.

Corrective control

A fictional safeguard intended to fix a weakness, restore an approved state, or reduce recurrence after detection.

Recovery control

A fictional safeguard intended to restore services, data, identities, processes, communication, or business capability after disruption.

Compensating control

A fictional alternate safeguard used when the preferred control is not practical, provided it addresses the same risk objective within an approved scope.

Control objective

A fictional statement describing the security or business outcome a control must achieve.

Control design

A fictional description of how a control should work, who owns it, where it applies, which evidence it produces, and how it is tested.

Control effectiveness

A fictional judgment about whether a control is appropriately designed, implemented, operating, monitored, and reducing risk as intended.

Residual risk

The fictional risk remaining after selected controls, dependencies, limitations, exceptions, and uncertainty are considered.

Control assurance

Fictional evidence that a control is designed, operating, tested, monitored, reviewed, and improved by accountable owners.

Treatment Options

Five Ways to Treat Fictional Risk

Avoid

When it fits

The fictional activity creates risk beyond appetite, offers limited business value, cannot be controlled reasonably, or depends on an unacceptable condition.

Fictional example

Retire the unsupported legacy export path instead of continuing to expose confidential data through an obsolete workflow.

Required evidence

Business-value review, risk scenario, control limits, cost, dependencies, alternatives, owner decision, and retirement plan.

Important limit

Avoidance may introduce operational, user, contractual, or transition effects that still require planning.

Reduce

When it fits

The fictional activity remains valuable and practical controls can lower likelihood, impact, exposure, or uncertainty.

Fictional example

Expire stale supplier access, reduce role scope, enable monitoring, strengthen review, and validate offboarding.

Required evidence

Control design, owner, implementation plan, validation, monitoring, rollback, operating evidence, and residual-risk estimate.

Important limit

Reduction rarely removes all risk and may create dependencies or unintended service effects.

Transfer

When it fits

A fictional contract, insurance concept, managed service, supplier obligation, or alternate provider can absorb part of the consequence or operation.

Fictional example

Use a fictional managed recovery provider with documented restoration duties and service commitments.

Required evidence

Contract scope, responsibility matrix, service level, incident duties, evidence rights, testing, exit plan, and retained-risk record.

Important limit

Accountability, data protection, oversight, and residual risk cannot be transferred completely.

Accept

When it fits

The fictional residual risk is within appetite, treatment cost exceeds benefit, temporary constraints exist, or the risk is low and monitored.

Fictional example

Accept a short-term reporting delay while a replacement control is implemented under a six-week approved exception.

Required evidence

Risk rationale, owner authority, scope, duration, controls, impact, residual risk, review trigger, expiration, and approval.

Important limit

Acceptance without authority, expiration, monitoring, and reassessment becomes unmanaged risk.

Monitor

When it fits

The fictional risk is changing, evidence is incomplete, exposure is low, controls are healthy, or a decision depends on a future trigger.

Fictional example

Monitor a low-volume supplier connection while collecting complete activity evidence and confirming business need.

Required evidence

Indicators, thresholds, sources, source health, owner, review cadence, escalation trigger, and decision deadline.

Important limit

Monitoring is not passive delay and does not replace action when supported risk exceeds tolerance.

Control Families

Eight Control Families for Fictional Treatment Plans

Governance and policy controls

Purpose

Define fictional direction, authority, ownership, exceptions, escalation, review, and accountability.

Examples

Policy approval, risk authority, exception process, responsibility matrix, review calendar, and decision log.

Evidence

Approved documents, owner records, decisions, reviews, exceptions, escalation outcomes, and closure records.

Failure risk

Requirements exist without accountable decisions or current ownership.

Administrative and process controls

Purpose

Standardize fictional onboarding, offboarding, access review, change, supplier review, incident response, backup, and recovery activities.

Examples

Procedures, checklists, approvals, separation of duties, training, ticket workflows, and periodic reviews.

Evidence

Completed records, approvals, training, tickets, reviews, exceptions, and operating metrics.

Failure risk

Processes are documented but performed inconsistently or without evidence.

Identity and access controls

Purpose

Limit fictional access to approved people, services, partners, roles, tasks, times, conditions, and resources.

Examples

Least privilege, temporary activation, strong authentication, federation controls, access review, expiration, and emergency access.

Evidence

Role maps, session records, approvals, access reviews, lifecycle actions, denied tests, and owner validation.

Failure risk

Broad or stale capability remains beyond current business need.

Data-protection controls

Purpose

Protect fictional data through classification, access, encryption, keys, retention, versioning, logging, backup, restore, and approved sharing.

Examples

Data-owner approval, encryption, key separation, object logging, versioning, lifecycle, backup coverage, and restore tests.

Evidence

Configuration, key records, access events, versions, retention, backups, restore results, and owner decisions.

Failure risk

Important copies, keys, retention paths, or recovery requirements remain unprotected.

Network and architecture controls

Purpose

Limit fictional reachability, segmentation, egress, trust paths, administrative access, and alternate routes.

Examples

Private endpoints, narrow routes, segmentation, egress restriction, management zones, service policies, and tested deny paths.

Evidence

Architecture, routes, effective reachability, rules, flow records, change history, tests, and rollback.

Failure risk

A wider path remains even though a narrow approved path exists.

Monitoring and detection controls

Purpose

Identify fictional access, changes, failures, drift, supplier activity, control exceptions, incidents, and recovery problems.

Examples

Audit logs, source-health monitoring, alerts, detection logic, review queues, dashboards, thresholds, and escalation.

Evidence

Expected events, delivery, parsing, retention, source health, alerts, investigations, tuning, and action records.

Failure risk

Blind spots or unreliable metrics weaken detection and validation.

Corrective and recovery controls

Purpose

Restore fictional approved state, service, data, identities, controls, and business capability after failure or disruption.

Examples

Rollback, remediation, restore, alternate process, reconfiguration, recovery exercise, user validation, and lessons learned.

Evidence

Action logs, prior state, recovery points, restore tests, user checks, monitoring, owner signoff, and closure.

Failure risk

A change is completed without proving service, data, and control recovery.

Physical and environmental controls

Purpose

Protect fictional facilities, equipment, people, power, communication, and alternate-work capabilities.

Examples

Controlled entry, equipment protection, alternate site, power resilience, secure storage, and remote-work procedures.

Evidence

Access records, inspections, tests, maintenance, exercises, incident records, and owner review.

Failure risk

Technical plans assume facilities and people will always remain available.

Selection Criteria

Eight Questions before Selecting a Fictional Control

Risk reduction

Strong selection

The fictional control directly lowers likelihood, impact, exposure, uncertainty, or dependency for the stated scenario.

Weak selection

The control is popular but does not address the actual risk path.

Reviewer question

Which part of the risk scenario does this control change?

Business fit

Strong selection

The fictional control supports required services, users, deadlines, accessibility, legal concepts, and minimum service levels.

Weak selection

The control reduces risk but makes the approved service unusable.

Reviewer question

Can the organization still perform the required business activity?

Feasibility

Strong selection

The fictional control is technically and operationally practical with available people, skills, tools, suppliers, time, and authority.

Weak selection

The plan depends on capabilities or approvals that do not exist.

Reviewer question

Can accountable owners implement and sustain this control?

Evidence and confidence

Strong selection

The fictional control choice is supported by relevant, healthy, current, traceable evidence with documented limitations.

Weak selection

The control is chosen from assumption or one unverified alert.

Reviewer question

How strongly does the evidence support the treatment choice?

Dependency impact

Strong selection

The fictional control accounts for identities, data, networks, suppliers, users, recovery, monitoring, and alternate processes.

Weak selection

The control breaks an undocumented dependency or creates a new concentration risk.

Reviewer question

Which connected services or owners could be affected?

Validation and rollback

Strong selection

The fictional control has approved tests, expected allowed and denied outcomes, monitoring, rollback, and decision thresholds.

Weak selection

The control is deployed globally with no staged test or reversal plan.

Reviewer question

How will success, failure, and safe reversal be proven?

Sustainability

Strong selection

The fictional control has clear ownership, operating procedure, funding, maintenance, training, metrics, review, and lifecycle support.

Weak selection

The control works once but cannot be maintained.

Reviewer question

Who will operate, monitor, fund, and review the control over time?

Residual risk and assurance

Strong selection

The fictional remaining risk, evidence confidence, exception need, owner authority, review date, and closure criteria are documented.

Weak selection

The treatment is called complete without evaluating what remains.

Reviewer question

What risk remains, who accepts it, and what proves closure?

Treatment Register

Northbridge Fictional Treatment Records

NBR-TRT-01

Expired supplier access exception

Reduce

Selected controls

Confirm sponsor, expire or renew account, narrow service access, enable complete activity logging, monitor, and validate offboarding.

Treatment owner

Third-Party Risk Owner

Validation

Supplier access fails after removal or matches renewed scope; approved internal service continues.

Residual risk

Low-Medium after verified removal or narrow renewal.

Evidence limit

No unauthorized use or disclosure is confirmed.

NBR-TRT-02

Critical reporting service lacks business recovery owner

Reduce

Selected controls

Assign business owner, confirm RTO and minimum service, test user validation, document escalation, and review residual recovery risk.

Treatment owner

Business Service Executive

Validation

Business owner approves recovery priority and participates in the next exercise.

Residual risk

Low after ownership and exercise evidence.

Evidence limit

Technical recovery capability already exists.

NBR-TRT-03

Incomplete quarterly access review

Reduce

Selected controls

Complete overdue review, prioritize privileged access, document decisions, automate reminders, escalate delays, and monitor completion.

Treatment owner

Identity Governance

Validation

All scoped roles are reviewed, decisions are recorded, and inappropriate access is removed if identified.

Residual risk

Low-Medium depending on findings.

Evidence limit

No specific inappropriate access is confirmed before review.

NBR-TRT-04

Leadership compliance metric has unclear denominator

Reduce

Selected controls

Define scope, denominator, exclusions, source health, confidence, trend, target, owner, and decision use.

Treatment owner

Security Metrics Owner

Validation

A reviewer can reconstruct the measure and identify included and excluded systems.

Residual risk

Low after corrected reporting.

Evidence limit

The measured controls may already perform strongly.

NBR-TRT-05

Supplier offboarding recurrence

Reduce

Selected controls

Assign policy, procedure, control, sponsor, identity, monitoring, and review owners; test the process; track exceptions.

Treatment owner

Governance Improvement Lead

Validation

A fictional offboarding exercise removes access, records evidence, notifies owners, and closes within the target.

Residual risk

Medium-Low after repeated evidence.

Evidence limit

Current operational changes may be partially undocumented.

NBR-TRT-06

Historical support collection outside backup scope

Accept or Reduce

Selected controls

Validate reproducibility, reconstruction time, classification, uniqueness, retention, owner approval, or add backup coverage.

Treatment owner

Support Data Owner

Validation

A reconstruction or restore test meets the approved recovery objective.

Residual risk

Depends on validation outcome.

Evidence limit

No current data loss is confirmed.

NBR-TRT-07

Standing privileged cloud-security role

Reduce

Selected controls

Move to temporary activation, preserve emergency access, monitor sessions, test response timing, and review exceptions.

Treatment owner

Identity Governance

Validation

Approved tasks succeed within target time; standing access is absent; emergency procedure works.

Residual risk

Low-Medium after testing.

Evidence limit

One emergency duty may require a documented exception.

NBR-TRT-08

Unsupported legacy export path

Avoid

Selected controls

Retire the legacy path, migrate approved workflows, preserve required records, validate users, monitor, and complete decommissioning.

Treatment owner

Application Service Owner

Validation

Approved exports use the replacement path and the legacy route, role, and storage dependency are removed.

Residual risk

Low after complete retirement.

Evidence limit

Transition effects require staged planning and user communication.

Implementation Workflow

Move from Risk Decision to Control Assurance

1

Confirm the fictional treatment decision

Restate the risk scenario, asset, owner, scope, evidence, likelihood, impact, confidence, authority, appetite, and required decision.

Output: Treatment decision record.

2

Compare treatment options

Evaluate fictional avoidance, reduction, transfer, acceptance, and monitoring using business value, feasibility, dependencies, cost, uncertainty, and timing.

Output: Treatment-options matrix.

3

Select control objectives

Define the fictional outcome each preventive, detective, corrective, recovery, governance, technical, administrative, or compensating control must achieve.

Output: Control-objective map.

4

Design the control set

Assign fictional scope, owner, implementation, evidence, dependencies, procedure, training, metrics, exception path, and lifecycle.

Output: Control-design package.

5

Plan sequence and change safety

Document fictional prerequisites, staged rollout, validation, expected allowed and denied outcomes, rollback, communication, and monitoring.

Output: Implementation and rollback plan.

6

Validate effectiveness

Test fictional design, operation, evidence, user function, business fit, failure behavior, recovery, source health, and owner approval.

Output: Control-validation record.

7

Evaluate residual risk

Reassess fictional likelihood, impact, confidence, limitations, exceptions, dependencies, and remaining decisions after control validation.

Output: Residual-risk decision.

8

Monitor and close

Track fictional metrics, failures, incidents, drift, exceptions, reviews, improvement actions, reassessment triggers, and closure evidence.

Output: Treatment assurance and closure package.

Fake Dashboard

Fake Northbridge Risk Treatment Dashboard

Training dashboard for fictional treatment and control evidence only.

Treatment records

8

Supplier access, recovery ownership, access review, metrics, offboarding, backup, privilege, and legacy workflow risks are mapped.

Immediate reductions

4

Stale access, missing ownership, incomplete access review, and unsupported broad privilege require prioritized action.

Confirmed incidents

0

The supplied fictional evidence supports risk and control gaps but no confirmed incident or disclosure.

Fake SOC Alert

Risk Treatment Deployed without Dependency Validation

Source: Fake Risk Treatment Console • Time: 1:20 PM

High Severity
A fictional least-privilege role reduction was staged, but the approved export workflow failed because one metadata dependency was not documented in the control design.
Defensive recommendation: Preserve the failed test as evidence, roll back, map the dependency, confirm whether it remains necessary, redesign the workflow, restore monitoring, retest approved success and denied excess access, document residual risk, and do not assume implementation alone proves control effectiveness.

Fake Log Panel

Fake Northbridge Treatment Review Records

training-log-viewer.log
09:00 DECISION risk='supplier stale access' treatment='Reduce'
09:08 CONTROL sponsor-review='required' account-expiration='required'
09:16 VALIDATE supplier-access='remove or narrow renew'
09:24 DECISION recovery-owner-gap treatment='Reduce'
09:32 CONTROL business-owner='assign' exercise='schedule'
09:40 DECISION historical-backup treatment='Accept or Reduce'
09:48 EVIDENCE reconstruction-test='missing'
09:56 DECISION privileged-role treatment='Reduce'
10:04 CONTROL temporary-activation='planned'
10:12 DECISION legacy-export treatment='Avoid'
10:20 CHANGE role-reduction='staged'
10:28 TEST export='failed' dependency='undocumented'
10:30 ROLLBACK role='restored'
10:40 REDESIGN dependency='replacement planned'
10:52 ASSURANCE implementation='not equal effectiveness'
11:00 CLOSE requires='validation + residual risk + owner'

Training note: this is fake data for defensive analysis practice only.

Findings Matrix

Northbridge Treatment Findings and Limits

NBR-TRT-F01High

The fictional supplier-access risk should be reduced rather than merely monitored because the exception expired, the account remains active, and authorized owner action is available.

Evidence support

Expired exception, active account, completed project, sponsor record, limited service scope, incomplete activity evidence, and offboarding procedure.

Alternative

A current business need may justify narrow renewal after formal approval.

Limitation

No unauthorized use or disclosure is confirmed.

NBR-TRT-F02Medium-High

The fictional historical support collection requires either validated risk acceptance or added recovery protection; an undocumented backup exclusion is not a complete treatment.

Evidence support

Data classification, backup map, recovery objective, reproducibility claim, retention, owner record, and missing reconstruction test.

Alternative

The collection may be safely reproducible within the approved time target.

Limitation

No current data loss is confirmed.

NBR-TRT-F03Medium-High

The fictional standing privileged role should move to temporary activation only after response timing, emergency access, session monitoring, and service dependencies are tested.

Evidence support

Role scope, task frequency, temporary activation capability, emergency process, session evidence, and owner review.

Alternative

A narrow standing emergency role may remain necessary for one documented duty.

Limitation

Availability impact is not fully known before staged validation.

NBR-TRT-F04High

The fictional legacy export path is a strong avoidance candidate because it provides limited current value and requires broad access, wider routing, and unsupported dependencies.

Evidence support

Workflow inventory, user demand, role scope, network path, storage dependency, maintenance status, and replacement design.

Alternative

A small user group may still require a temporary migration period.

Limitation

Retirement must preserve required records and approved user workflows.

NBR-TRT-F05High

The fictional treatment plan should prioritize active stale access and missing ownership before metric redesign and lower-impact documentation updates.

Evidence support

Current access capability, expired approval, critical recovery ownership gap, decision deadlines, business impact, and remediation readiness.

Alternative

Leadership may reorder work during a major reporting deadline or active incident.

Limitation

Final order requires fictional risk-owner approval.

NBR-TRT-F06High

No fictional treatment can be considered complete until control effectiveness, business function, residual risk, owner approval, monitoring, and closure evidence are validated.

Evidence support

Treatment records, failed-change lessons, control objectives, operating evidence, recovery needs, exception rules, and review requirements.

Alternative

Emergency containment may temporarily precede full validation when immediate risk requires action.

Limitation

Emergency actions still require later review and evidence.

Analyze the Evidence

What Does the Failed Control Test Mean?

The fictional export role had broader storage access than the redesigned workflow appeared to require.
A staged role reduction caused the approved export job to fail.
Application review identified an undocumented metadata dependency.
The change was rolled back.
No unauthorized access or incident is shown.
The dependency can be replaced and the narrower role can be retested.

Which conclusion is strongest?

Common Mistakes

Mistakes That Weaken Risk Treatment and Control Selection

Choosing a fictional control before defining the exact risk scenario and control objective.
Treating avoidance, reduction, transfer, acceptance, and monitoring as interchangeable.
Assuming risk transfer removes organizational accountability.
Accepting fictional residual risk without documented authority, scope, reason, duration, controls, monitoring, and review.
Calling monitoring a treatment when no thresholds, source health, owner, trigger, or decision deadline exist.
Selecting a technically strong control that breaks required business service or accessibility.
Deploying identity, network, storage, or process changes globally without staged validation and rollback.
Listing fictional controls without checking design, implementation, operation, evidence, monitoring, ownership, and sustainability.
Using a compensating control that does not address the same risk objective as the preferred control.
Treating a completed ticket or configuration change as proof of control effectiveness.
Ignoring people, supplier, process, facility, recovery, and communication controls because the risk appears technical.
Failing to reassess residual likelihood, impact, confidence, and limitations after implementation.
Closing treatment while exceptions, missing evidence, failed tests, ownership gaps, or review actions remain open.
Using or exposing any real company controls, internal architecture, supplier contract, risk acceptance, employee record, school data, credential, incident evidence, or confidential business information.

Safe Practice Lab

Build the Northbridge Risk Treatment and Control Selection Package

Your fictional assignment

Treatment Options, Control Objectives, Validation, Residual Risk, and Assurance

Use only the supplied fictional Northbridge records to complete an end-to-end risk-treatment and control-selection review.

Required deliverables

  1. Treatment charter with risk scenario, scope, owners, authority, evidence, appetite, privacy, and decisions.
  2. Avoid, reduce, transfer, accept, and monitor options matrix.
  3. Preventive, detective, corrective, recovery, governance, administrative, technical, physical, and compensating control map.
  4. Control objectives, design, owners, procedures, evidence, dependencies, metrics, and lifecycle.
  5. Implementation plan with prerequisites, sequence, staged tests, communication, monitoring, and rollback.
  6. Control-effectiveness validation and failed-test analysis.
  7. Residual-risk decision with confidence, limitations, exceptions, review triggers, and approval.
  8. Technical summary, leadership summary, reflection, and portfolio-safety statement.
Complete the lab only with fictional evidence displayed on this page. Do not use real company controls, architecture, supplier contracts, employee records, school data, credentials, incidents, or confidential business information.

Scenario Decision Lab

A Preferred Control Would Break a Required Workflow

The fictional strictest role reduction would stop approved exports, but a narrower redesign can remove unnecessary access while preserving the business function.

Scenario Decision Lab

A Historical Data Collection May Be Reproducible

The fictional support data owner believes an older collection can be rebuilt, but no reconstruction test exists.

Defender Habits

Risk Treatment and Control Selection Checklist

Check Your Understanding

I14.4 Mini Quiz: Risk Treatment and Control Selection

Choose your answers first. Explanations appear only after submission.

1. What is fictional risk treatment?

2. When is fictional risk avoidance most appropriate?

3. What does fictional risk transfer accomplish?

4. What makes a fictional compensating control defensible?

5. What should happen before a major fictional control change?

6. Who should normally accept fictional residual business risk?

7. What makes a fictional treatment finding defensible?

Portfolio Prompt

Portfolio Prompt

Create a fictional Risk Treatment and Control Selection Package for Northbridge. Include the treatment charter, option comparison, control objectives, control-family map, business-fit analysis, evidence and confidence review, dependency analysis, implementation sequence, staged validation, expected allowed and denied behavior, rollback, monitoring, control assurance, residual-risk decision, exceptions, owners, review triggers, leadership summary, reflection, and a portfolio-safety statement.

Use only fictional risks, assets, controls, owners, suppliers, evidence, dates, tests, metrics, and decisions.
Do not treat a completed implementation, strict control, supplier contract, or transferred duty as proof that risk is eliminated.
Make every control traceable to the exact risk objective and every treatment traceable to an authorized owner.
Preserve failed tests, dependencies, alternatives, residual risk, and the difference between technical control operation and business risk acceptance.

Key Takeaways

What You Should Remember

1.Risk treatment includes avoidance, reduction, transfer, acceptance, and monitoring.
2.Control selection should begin with the exact risk scenario and control objective.
3.The strongest control is not always the safest control if it breaks required business service or recovery.
4.Implementation does not prove control effectiveness.
5.Risk transfer never removes all organizational accountability.
6.Residual risk requires authorized ownership, current evidence, documented limits, and reassessment.
7.Portfolio artifacts should use fully fictional treatment evidence and never expose real organizational records.

Navigation

Continue Module I14