Residual risk is the risk that remains after security controls, safeguards, or mitigation measures have been implemented. No practical security program can eliminate every threat or vulnerability completely, so organizations evaluate the remaining exposure to determine whether additional treatment is required or whether management can formally accept it.
The distinction from inherent risk is particularly important. Inherent risk represents the level of exposure before controls are applied. For example, an internet-facing application containing sensitive information may have substantial inherent risk. After implementing strong authentication, patching, a web application firewall, monitoring, secure coding controls, and segmentation, its probability and impact of compromise may be reduced—but not eliminated. The remaining exposure is residual risk.
“Acceptable risk” describes risk that falls within an organization's approved tolerance or appetite; residual risk may or may not be acceptable. If the remaining exposure still exceeds tolerance, further controls, avoidance, transfer, or other treatment may be necessary. “Appropriate” is not a formal risk category in this context.
Risk management therefore follows a continuous cycle of identifying inherent exposure, applying controls, measuring the remaining residual exposure , and comparing that level with organizational risk tolerance.
Study Guide Reference: Vulnerability Management → Risk Analysis → Inherent Risk → Mitigating Controls → Residual Risk → Risk Acceptance → Risk Appetite and Tolerance.