Case AA03D9 · GRC · L3 Applied
Risk Appetite and Tolerance
Practise as: Explain it · Interview
Interview questionHow would you define and operationalize a cyber risk appetite so that it actually drives decisions?
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- Appetite: the amount and type of risk the board is willing to pursue for objectives. Set by the board, not security.
- Tolerance: measurable acceptable deviation, e.g. no critical internet-facing vuln open more than 7 days.
- Operationalize with KRIs and thresholds (green/amber/red) that trigger escalation when breached.
- Risk acceptance must be time-bound, owned by a business exec, and re-reviewed; exceptions register tracks them.
- Qualitative statements (low appetite for data loss) should translate into quantitative loss bounds where possible.
If the interviewer pushes back
- A product VP wants to launch with a known high-risk finding. Walk through how appetite and tolerance decide this.
- How do you avoid KRIs that are easy to measure but do not predict loss?
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.