

Gary Hinson CEO of IsecT Ltd
Information risk and security consulting
ISO27k Audit ISMS templates and policies
Pragmatic Security Metrics (with Krag Brotby)
Cybersecurity Hyperglossary (forthcoming!)
________________________________________
--
You received this message because you are subscribed to the Google Groups "Cybersecurity hyperglossary" group.
To unsubscribe from this group and stop receiving emails from it, send an email to hyperglossar...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/hyperglossary/CAPRmHF54hWWsZ-PhYmmx2EVfAdyn%2BuAvK_cNGxoudvTHKrfycQ%40mail.gmail.com.
Gary Hinson CEO of IsecT Ltd
Information risk and security consulting
ISO27k Audit ISMS templates and policies
Pragmatic Security Metrics (with Krag Brotby)
Cybersecurity Hyperglossary (forthcoming!)
________________________________________
To view this discussion visit https://groups.google.com/d/msgid/hyperglossary/CAJBCom3OpXU2%3D1oPqKUs4uqBB%3DFVRuMhtY9T2-HCnz60WH36VQ%40mail.gmail.com.
My definition for the “appetite for risk” has always been less mathematical, and more emotional.
We cannot put these into numbers, because the company might have a risk using a 3x3 matrix, - Likelihood 1, Impact 1, Risk level of two in our SRMP is “Acceptable, treatment recommended”.
This same persons’ tolerance for risk is also an emotional value, and not one so easily put to numbers – as it is tied to their appetite for risk.
As a company, we mathematically accept this risk, even without treatment. Our CFO does not “like” this; accepting risk without treatment is being made to eat her steamed vegetables without salt and pepper. Keeping with this analogy, the CFO fills up quickly because of a low tolerance for risk, and graduates to a near-zero appetite.
An idea of the inverse – one of my Tech guys has a moderate appetite for risk, that they feel closely align with our SRMP. They also have a fairly high tolerance for risk, and thus:
Once again with the analogy, even though we continue to mathematically accept this risk, even without treatment. My tech guy is fine accepting risk without treatment – all youi can eat buffet, quality means very little to this hungry guy. However, enough bad bain-marie food and the tech guy becomes more cautious – only eating from the dishes he knows agree with him.
To summarise:
So in my case, there is only positive integer descriptions for risk tolerance ("None", "Some", "Heaps")
This of course is just my 2 cents. Keen to hear other folks’ food-laden analogies!
Kind Regards,
Joel McLean

Gary Hinson CEO of IsecT Ltd
Information risk and security consulting
ISO27k Audit ISMS templates and policies
Pragmatic Security Metrics (with Krag Brotby)
Cybersecurity Hyperglossary (forthcoming!)
________________________________________
"risk appetite | This is a vague notion or concept without much practical value."
Probably a bit naff for your book, but damn, that's a fine definition!
--
You received this message because you are subscribed to the Google Groups "Cybersecurity hyperglossary" group.
To unsubscribe from this group and stop receiving emails from it, send an email to hyperglossar...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/hyperglossary/19f2e89d-3141-4207-8bfd-77169c84ff0en%40googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/hyperglossary/CAPRmHF609YnHKriwJ3EAYr%3DBgd_kCQR1VgNV5%2B%2BAXd88F9qsKg%40mail.gmail.com.

Risk appetite can be defined as 'the amount and type of risk that an organisation is willing to take in order to meet their strategic objectives'. Organisations will have different risk appetites depending on their sector, culture and objectives. A range of appetites exist for different risks and these may change over time.
Risk appetite and tolerance need to be high on any board's agenda and is a core consideration of an entreprise risk management approach. Our guidance provides practical direction, advice and information to support boardroom debate.
While risk appetite will always mean different things to different people, a properly communicated, appropriate risk appetite statement can actively help organisations achieve goals and support sustainability.
Gary Hinson CEO of IsecT Ltd
Pragmatic Security Metrics (with Krag Brotby)
Cybersecurity Hyperglossary (forthcoming!)
________________________________________
To view this discussion visit https://groups.google.com/d/msgid/hyperglossary/CAJBCom222H8j_V8radT2sQmPC9eeB-%2Bc3e0oMOZzpOGAzUWrVg%40mail.gmail.com.
To view this discussion visit https://groups.google.com/d/msgid/hyperglossary/CAPRmHF46C2UxXk8BWQyYW4EL%2BpPmOGqeNYGWWZpEpSqOATbzyQ%40mail.gmail.com.