Three simple steps to determine risk tolerance
For Chief Information Security Offiers, in addition to deciding what policies, processes, or technology an organisation should have in place, an even more significant challenge is successfully negotiating disputed risk issues.
But, the process for determining risk tolerance is fraught with organisational politics, and it goes without saying that each organisation's circumstance needs a customised fit. When determining a process, the most important aspects to take into account include: how an organisation decides on risk tolerance, security risk assumption decision-making, and who has the authority to assume security risks.
Every organisation has a risk tolerance model, ranging from a formal documented process to an undocumented process, or more often than not something in between. To solve the problem, first you need to determine where on this spectrum your organisation lies.