Home > Glossary > Certified in Cybersecurity > Risk Mitigation

📖 What is Risk Mitigation?

Risk Mitigation involves implementing controls and countermeasures to reduce the likelihood or the impact of an identified threat. This strategy focuses on bringing the risk down to an acceptable level, often through technical solutions, policy changes, or improved employee training.

🥋 Sensei Says:

"Distinguish this from "Avoidance." Mitigation does not stop the business activity entirely; it simply makes the associated risk manageable through controls."

📚 Certification: Certified in Cybersecurity (CC)

🔑 What are the Key Concepts of Risk Mitigation?

  • Administrative controls use policies and procedures, such as security awareness training, to mitigate risks by changing human behavior and organizational standards.
  • Technical controls implement hardware or software solutions, like firewalls and encryption, to automatically reduce the likelihood of a successful cyber attack.
  • Physical controls involve tangible barriers, such as locks and security cameras, to mitigate risks associated with unauthorized physical access to assets.
  • Residual risk is the level of risk that remains after mitigation controls have been implemented; this remaining risk must be formally accepted by management.
  • Defense in Depth employs multiple layers of mitigation controls so that if one security measure fails, others remain to protect the critical asset.

🎯 How does Risk Mitigation appear on the CC Exam?

You may be asked to identify the correct risk treatment strategy when a company decides to implement multi-factor authentication to reduce the risk of unauthorized account access while continuing to provide remote services.

A scenario might describe a business that refuses to stop a profitable project despite security flaws but chooses to install a Web Application Firewall to lower the risk to an acceptable level.

Expect questions that require you to distinguish between risk avoidance and mitigation, specifically when a company chooses to secure a process through controls rather than eliminating the activity entirely.

❓ Frequently Asked Questions

How does risk mitigation differ from risk transference?

Mitigation focuses on reducing the risk through internal controls, whereas transference shifts the financial or operational burden to a third party, such as through a cyber insurance policy or outsourcing.


What is the relationship between mitigation and residual risk?

Mitigation aims to lower risk, but it rarely eliminates it entirely. The risk that remains after controls are applied is called residual risk, which the organization must then formally accept.

Related Terms from Certified in Cybersecurity

📝 Related Study Guides

Study Guide 8 min read

ISC2 CC Certification Guide: Your Free Entry into Cyber

The ISC2 Certified in Cybersecurity (CC) is a free, entry-level certification designed for beginners. It covers five core domains—Security Principles, BCP/DR, Access Control, Network Security, and Security Operations—via a 100-question exam. It's the ideal starting point for career changers to build a foundation without financial barriers.

Exam Tips 8 min read

ISC2 CC Exam Domains: What You Need to Know to Pass

The ISC2 CC exam consists of five domains: Security Principles, Business Continuity (BC), Disaster Recovery (DR), and Incident Response (IR), Access Controls, Network Security, and Security Operations. To pass, you must master the CIA Triad and security governance, while prioritizing high-weight domains through targeted practice and domain-specific analytics.

Deep Dive 10 min read

Mastering the CIA Triad for ISC2 CC: A Deep Dive

The CIA triad is the foundational model of information security, consisting of Confidentiality (preventing unauthorized access), Integrity (ensuring data accuracy and consistency), and Availability (guaranteeing reliable access to resources). Balancing these three pillars allows security professionals to manage risk effectively and protect organizational assets against diverse cyber threats.

🧠

Test Your Knowledge

Think you understand Risk Mitigation? Put it to the test with our practice exam.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium