The level of risk an organisation is willing to accept in pursuit of its objectives.
Risk appetite defines how much risk an organisation is willing to accept in pursuit of its objectives. It's set by leadership and guides risk treatment decisions—risks within appetite can be accepted; those exceeding appetite require treatment. Risk appetite varies by risk type and context. A startup might accept more operational risk for growth; a healthcare provider might have very low appetite for patient data risk. Clear risk appetite enables consistent, appropriate risk decisions.
Why It Matters
The DSC Perspective:
Without defined risk appetite, risk decisions are inconsistent and lack accountability. Define risk appetite at the leadership level so security teams know which risks require treatment and which can be accepted.
