Risk Tolerance
What is Risk Tolerance?
The acceptable level of variation an organisation is willing to tolerate around specific risk objectives. Risk tolerance provides specific, measurable thresholds that translate the broader risk appetite into operational guidance.
Terms that appear alongside risk tolerance
Each of these is named in at least one of the same controls as risk tolerance. The number is how many controls name both.
- risk appetite 10 shared controls
- nist 10 shared controls
- accountability 6 shared controls
- governance 6 shared controls
- audit 5 shared controls
- cybersecurity 5 shared controls
- policy 5 shared controls
- availability 4 shared controls
Frameworks that govern risk tolerance
What the standards actually require on risk tolerance
Requirements naming risk tolerance across 6 standards, quoted from the control text.
Organizational risk tolerances are determined and documented. Tolerance is written down at a level that lets someone decide whether a measured risk is acceptable, and it is traceable to an authority that can set it.
AIRMF-MP-1.5 · Organizational risk tolerances are determined and documented →Risk appetite and risk tolerance statements are established, communicated, and maintained
NIST-CSF-GV.RM-02 · Risk appetite and risk tolerance statements are established, communicated, and maintained →Conduct risk assessments at the three tiers defined in NIST SP 800-30 Rev 1 Section 2.3 and aligned with NIST SP 800-39 governance tiers.
NISTSP30-2 · Three-Tier Risk Assessment Scoping (Organisation, Mission/Business, Information System) →Vet mobile applications prior to deployment using static and dynamic analysis aligned with enterprise risk tolerance.
800-124r2-3.4 · Mobile Application Vetting →Define ISCM metrics per Section 3.2 covering security control effectiveness + system + organizational metrics + leading and lagging indicators + Cyber-Resilience metrics + KPIs (Mean Time to Detect MTTD + Mean Time to Respond MTTR + Mean Time to Remediate MTTR...
NISTSP137-2 · Monitoring Metrics, Measures, and Frequencies →Execute the Frame step per NIST SP 800-39 Chapter 3 Section 3.1. Framing produces a risk frame that establishes the context within which risk-based decisions are made.
NISTSP39-2 · Risk Framing: Risk Frame Components and Trust →Questions people ask about risk tolerance
What is Risk Tolerance?
Why is Risk Tolerance important for compliance?
Which compliance frameworks address Risk Tolerance?
Where can I learn more about Risk Tolerance?
See how Risk Tolerance applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.