5.5 Selecting Risk Responses: Avoid, Accept, Share, Mitigate, Transfer

Key Takeaways

  • The five recognized risk responses are avoid, accept, share, mitigate, and transfer, and every identified risk must resolve to exactly one of them.
  • Mitigation reduces likelihood or impact but never eliminates risk, so every mitigated risk leaves residual risk that must still be accepted by an authorized official.
  • Avoidance is the only response that removes the risk entirely, because it removes the activity that generates it.
  • Transfer and sharing move financial or operational consequences to another party but never move statutory or regulatory accountability.
  • Acceptance is a formal, documented decision by an official with the authority to make it, not the default outcome when nothing else is done.
Last updated: August 2026

Selecting Risk Responses: Avoid, Accept, Share, Mitigate, Transfer

Task 5.4 requires that a risk response be "assigned (e.g., avoid, accept, share, mitigate, transfer) based on identified vulnerabilities or deficiencies." These five options are exhaustive: every risk the assessment surfaces resolves to exactly one of them. The exam tests whether you can select the right one from a scenario and whether you know who is authorized to choose it.


1. The Five Responses

ResponseWhat HappensRisk AfterChoose When
AvoidEliminate the activity, capability, or asset that generates the riskZero — the risk no longer existsThe risk exceeds tolerance and the activity is not essential
MitigateImplement controls that reduce likelihood or impactReduced, never zeroThe activity is necessary and controls are cost-effective
TransferShift financial consequence to a third partyFinancially offset; operationally unchangedThe impact is quantifiable and insurable
ShareDistribute risk across parties through partnership or contractDistributedAnother party is better positioned to manage part of it
AcceptFormally decide to bear the risk without further actionUnchangedRisk is within tolerance, or mitigation costs more than the exposure

Avoid

The only response that reduces risk to zero, because it removes the source. Discontinuing a legacy file-transfer service, declining to collect a data element, or cancelling a feature all eliminate the associated risk entirely.

The cost is capability. Avoidance forgoes whatever benefit the activity provided, which is why it is appropriate only when the risk genuinely exceeds tolerance and the activity is not mission-essential. An exam scenario describing a marginal-value service with unacceptable risk is usually pointing at avoidance; one describing a mission-critical function is not.

Mitigate

The most common response and the one the RMF is built around. Controls reduce likelihood (patching, hardening, access restriction), impact (encryption, segmentation, backups), or both.

The essential property: mitigation never reaches zero. Every mitigated risk leaves residual risk, and that residual risk must still be formally accepted. Candidates often treat "mitigate" as terminal — it is not. Mitigation is followed by acceptance of what remains.

Transfer

Moves the financial consequence elsewhere — cyber liability insurance being the canonical example. The breach still happens; the money to respond comes from a policy.

[!IMPORTANT] Accountability is never transferable. Insurance can pay for breach response, notification, and legal costs. It cannot make the insurer responsible to the regulator. Under FISMA, HIPAA, or the GDPR, the agency head, covered entity, or controller remains accountable regardless of coverage. Exam options claiming that insurance or outsourcing "relieves the organization of liability" or "transfers statutory accountability" are always wrong.

Share

Often grouped with transfer, but distinct. Sharing distributes both the management and the consequence across parties — a cloud shared-responsibility model, a partnership, a consortium arrangement. Where transfer is mainly financial, sharing is operational: the cloud provider genuinely manages physical and hypervisor security, and genuinely bears the consequence of failing at it.

The residual obligation is that the sharing party must verify the other party's performance. Inheriting a control from a Cloud Service Provider still requires confirming the provider's authorization is current and that the customer-responsibility controls in the responsibility matrix are implemented locally. Sharing responsibility is not abandoning oversight.

Accept

A deliberate, documented decision to bear a risk without further action, appropriate when the residual risk is within organizational tolerance or when mitigation would cost more than the exposure it removes.

Acceptance is not what happens when nobody does anything. Unaddressed risk is not accepted risk — it is unmanaged risk, and it is a finding in its own right. Valid acceptance requires a decision by an official with the authority to make it, a documented rationale, a record in the risk register, and, in most organizations, a defined review date.


2. Who Decides

Authority is scoped by magnitude, and misattributing it is a common exam trap.

Risk LevelDecision Authority
Within a system, inside delegated toleranceSystem owner, per organizational policy
System-level residual risk affecting authorizationAuthorizing Official
Risk crossing multiple systems or missionsRisk Executive (Function)
Enterprise-level strategic riskExecutive leadership / head of agency

The Authorizing Official holds the non-delegable authority to accept residual risk for system authorization. An ISSO, system owner, or assessor may analyze, recommend, and prepare the package — none can accept the risk in the AO's place. Where a shared service creates risk for multiple consumers, escalation to the Risk Executive is correct, because no single system owner can accept a risk they impose on others.


3. Selecting the Right Response

Work through four questions in order:

  1. Is the activity essential? If not, and the risk exceeds tolerance → avoid.
  2. Are cost-effective controls available? If yes → mitigate, then accept what remains.
  3. Is a third party better placed to manage or absorb part of it? If yes → share or transfer — remembering that accountability stays put.
  4. Is the remaining risk within tolerance? If yes → accept formally. If no, return to step 2 with more resources, or escalate.

Responses Combine

Real decisions rarely use one response. A payment platform might mitigate through encryption and segmentation, share infrastructure risk with a PCI-compliant provider, transfer breach-response cost through cyber insurance, and accept the residual risk that remains — all for the same risk. Exam items describing layered arrangements are testing whether you can identify each component correctly rather than forcing a single label.

[!NOTE] Documenting the decision. Every response decision records the risk, the chosen response and its rationale, the decision-maker and date, and — for accepted risks — the review date. Mitigation decisions additionally generate POA&M entries with milestones and completion dates. Accepted risks live in the risk register without POA&M entries, because no corrective action is planned. Getting this routing right is directly examinable.

Loading diagram...
Selecting and Routing a Risk Response
Test Your Knowledge

An agency purchases a cyber liability policy covering breach notification, forensics, and legal costs for a system processing protected health information. What effect does this have on the agency's compliance posture?

A
B
C
D
Test Your Knowledge

A moderate-severity finding is documented in the assessment report, no corrective action is planned, no decision-maker is recorded, and the item simply remains open past authorization. How should this be characterized?

A
B
C
D
Test Your Knowledge

A system owner mitigates a high-severity deficiency by deploying network segmentation and enhanced monitoring, reducing the assessed risk from High to Low. What must still happen before authorization?

A
B
C
D