Which document is the primary source for defining the 'Risk Appetite' of an enterprise?
Trap 1: Security Policy
Policies implement rules, they do not define appetite.
Trap 2: Business Impact Analysis
Assesses impact, but does not define appetite.
Trap 3: Incident Response Plan
Reactive document, not strategic.
- A
Risk Appetite Statement
This defines the amount of risk an organization is willing to accept.
- B
Security Policy
Why wrong: Policies implement rules, they do not define appetite.
- C
Business Impact Analysis
Why wrong: Assesses impact, but does not define appetite.
- D
Incident Response Plan
Why wrong: Reactive document, not strategic.