When risk is above the organisation’s appetite, scoring alone is not enough. The asset owner needs a plan to address unacceptable risk: improve or add countermeasures, change policy and procedure, prioritise by relative risk, and weigh cost and complexity against effectiveness.
In Part 3-2 that plan shows up after comparisons with tolerable risk — at ZCR 4 (do we need detailed work?) and inside ZCR 5 (existing controls, residual risk, additional countermeasures). Programme-level policy for the same decisions sits in Part 2-1 ORG 2.1.
Related: Understand Risk | Balancing Security vs Cost | Mitigated Likelihood and Residual Risk | Four Ts of Managing Risk | ZCR 5 | ZCR 6 – CRS | ZCR 7 – Approval | SP and Risk Assessment
When residual risk is still above tolerance, apply the Four Ts of managing risk: Tolerate (accept under policy), Transfer (e.g. insurance or contractual allocation), Terminate (remove the exposure), or Treat (more or better controls). Record the decision. Moving an asset into a higher-security zone can also borrow that zone’s countermeasures.
Where the choice is Treat, structure countermeasures with the Five Ds and zone/conduit strategy. Recommendations should be independently checked for unintended safety or cybersecurity side effects before implementation. Adjusted mitigated likelihood (MTLa) is sometimes recorded to show the expected improvement if recommendations are implemented — see Mitigated Likelihood and Residual Risk.