CISSP Risk Management Explained
Dr. Abeer Alshammari · Published 7/29/2026
Domain 1 risk management questions hinge on precise vocabulary. Mixing up these terms is one of the most common sources of missed points for otherwise well-prepared candidates.
The four risk treatment options
- Mitigate -- reduce likelihood or impact by implementing a control
- Transfer -- shift financial impact to another party, typically via insurance or contract
- Avoid -- eliminate the risk by not engaging in the activity that creates it
- Accept -- knowingly take no further action, usually because cost of treatment exceeds the risk
Qualitative vs. quantitative analysis
Qualitative analysis uses relative ratings (low/medium/high) and is faster but subjective. Quantitative analysis assigns dollar values using formulas like Single Loss Expectancy (SLE = Asset Value × Exposure Factor) and Annualized Loss Expectancy (ALE = SLE × Annualized Rate of Occurrence). The exam expects you to recognize both approaches and when each is appropriate -- quantitative is more defensible for large capital decisions, qualitative is faster for routine triage.
Residual risk
Residual risk is what remains after controls are applied -- it is never zero. A common exam trap is an answer implying a control "eliminates" risk; the more defensible framing is that controls reduce risk to an acceptable residual level, which management then formally accepts.
Try it yourself
An interactive CyberAbeer experience for this topic is in development.
Coming soon