📖 What is Risk Tolerance?

Risk Tolerance defines the acceptable variation from the established risk appetite. It’s a measurable boundary, often expressed as a statistical range, indicating the amount of deviation an organization will accept before taking corrective action. Tolerance levels are specific to individual risks and business objectives.

🥋 Sensei Says:

"Think of tolerance as the ‘speed limit’ within the broader ‘highway’ of risk appetite. Exam questions may present scenarios requiring you to calculate or interpret tolerance levels. Distinguish tolerance from thresholds, which trigger immediate action."

📚 Certification: Certified Information Security Manager (CISM)

🔑 What are the Key Concepts of Risk Tolerance?

  • Risk tolerance is quantitatively defined, unlike risk appetite which is more qualitative and strategic.
  • Tolerance levels are risk-specific; a high tolerance for one risk doesn't imply a high tolerance for others.
  • Exceeding tolerance levels doesn't automatically mean failure, but triggers monitoring and potential corrective actions.
  • Tolerance is often expressed as a range (e.g., +/- 5%) around a target, providing a measurable boundary.
  • Understanding tolerance is crucial for effective risk reporting and escalation procedures within an organization.

🎯 How does Risk Tolerance appear on the CISM Exam?

You may be asked to determine the appropriate risk response based on whether a measured risk level falls within the defined tolerance range for a specific business process.

A scenario might describe a project exceeding its budget by a certain percentage – identify if this breach necessitates immediate escalation based on the established tolerance levels.

Expect questions about selecting the correct metrics to monitor and report against defined risk tolerances, ensuring timely identification of deviations.

❓ Frequently Asked Questions

What’s the difference between risk tolerance and risk threshold?

A threshold triggers immediate action (like shutting down a system), while tolerance allows for some deviation before requiring monitoring or corrective steps. Thresholds are stricter than tolerances.


How do you determine appropriate risk tolerance levels?

Tolerance levels are determined by considering the organization’s risk appetite, business objectives, and the potential impact of exceeding the tolerance. It’s a business decision, not purely technical.


Can risk tolerance change over time?

Yes, risk tolerance can be adjusted based on changes in the business environment, regulatory requirements, or the organization’s strategic goals. Regular review is essential.

Related Terms from Certified Information Security Manager

📝 Related Study Guides

Study Guide 10 min read

CISM Exam Study Guide: Pass the Security Management Exam

The CISM exam consists of 150 multiple-choice questions to be completed in 4 hours, requiring a scaled score of 450/800 to pass. It focuses on four key domains: Governance, Risk Management, Program Development, and Incident Management, prioritizing a managerial perspective over technical implementation to certify security leadership expertise.

Exam Tips 8 min read

Risk Appetite vs Risk Tolerance: ISACA Concepts Explained

Risk appetite is the broad, strategic amount of risk an organization is willing to accept to achieve its goals, typically set by the board. Risk tolerance is the tactical, measurable variation around those goals. While appetite defines the general direction, tolerance sets the specific boundaries for operational deviations.

Deep Dive 8 min read

How to Conduct a Tabletop Exercise: CISM Study Guide

A tabletop exercise is a discussion-based simulation where key stakeholders walk through a hypothetical security incident to validate the Incident Response Plan (IRP). It identifies gaps in communication and processes without impacting production systems, making it a cost-effective, low-risk method for ensuring organizational readiness and meeting CISM governance requirements.

🧠

Test Your Knowledge

Think you understand Risk Tolerance? Put it to the test with our practice exam.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium