Risk Reduction
What is Risk Reduction?
Actions taken to decrease the probability or impact of a risk event through the implementation of controls and other mitigation measures.
Frameworks that govern risk reduction
What the standards actually require on risk reduction
Requirements naming risk reduction across 3 standards, quoted from the control text.
Apply ATT&CK Mitigations (M-IDs) for prevention and risk reduction. M1015 Active Directory Configuration + M1018 User Account Management + M1027 Password Policies + M1056 Account Use Policies + M1017 User Training + M1036 Account Use Policies + M1042 Disable o...
MITRE-ATTACK-Mitigations-M-IDs-Active-Directory-User-Account-Management-Password-Policies-Network-Segmentation · MITRE ATT&CK Mitigations + M-IDs + Active Directory + User Account + Password + Network Segmentation + Application Control →Analyses output from defensive tooling and turns it into risk reduction rather than an alert backlog.
NICE-PD-WRL-001 · Defensive Cybersecurity →Execute the Monitor step per NIST SP 800-39 Chapter 3 Section 3.4. Risk monitoring must address (a) effectiveness of risk responses (are implemented controls and other responses achieving intended risk reduction), (b) changes to information systems and operati...
NISTSP39-5 · Risk Monitoring: Effectiveness, Changes, Compliance, and Reassessment Triggers →Questions people ask about risk reduction
What is Risk Reduction?
Why is Risk Reduction important for compliance?
Which compliance frameworks address Risk Reduction?
Where can I learn more about Risk Reduction?
See how Risk Reduction applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.