Open cardosec

Case AA03D9 · GRC · L3 Applied

Risk Appetite and Tolerance

Practise as: Explain it · Interview

Interview questionHow would you define and operationalize a cyber risk appetite so that it actually drives decisions?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Appetite: the amount and type of risk the board is willing to pursue for objectives. Set by the board, not security.
  2. Tolerance: measurable acceptable deviation, e.g. no critical internet-facing vuln open more than 7 days.
  3. Operationalize with KRIs and thresholds (green/amber/red) that trigger escalation when breached.
  4. Risk acceptance must be time-bound, owned by a business exec, and re-reviewed; exceptions register tracks them.
  5. Qualitative statements (low appetite for data loss) should translate into quantitative loss bounds where possible.

If the interviewer pushes back

  • A product VP wants to launch with a known high-risk finding. Walk through how appetite and tolerance decide this.
  • How do you avoid KRIs that are easy to measure but do not predict loss?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.