A board minutes note says ransomware risk is "accepted," but there is no rationale, risk owner, residual description, or review date. What is missing for valid acceptance?
Select an answer to reveal the explanation.
Short Explanation
Real acceptance looks like a signed decision with a name on it — not a sticky note that says "we'll live with it" and then everyone forgets. No owner, no rationale, no review? That's neglect wearing an acceptance costume.
Full Explanation
Proper risk acceptance is deliberate: the residual risk is described, judged within appetite, assigned an owner, recorded, and scheduled for review. A bare statement that ransomware is "accepted" without those elements is accidental neglect, not a treatment decision. Governance requires documentation so leaders can revisit the choice as threats and controls change.