# Risk Appetite Statement Development Framework - **PURPOSE:** Guides the creation of clear, actionable security risk appetite statements that connect security governance to business objectives. - **WHEN TO USE:**When establishing or refreshing security risk appetite, aligning security with enterprise risk management, or enhancing board-level risk oversight. ## STEP 1: UNDERSTAND BUSINESS CONTEXT - Review enterprise strategy and objectives - Identify critical business processes and assets - Understand regulatory and compliance requirements - Document key business constraints and enablers ## STEP 2: DEFINE RISK CATEGORIES For each of these common security risk categories: - Data Breach/Information Disclosure - System Availability/Business Disruption - Regulatory Compliance - Third-Party/Supply Chain - Emerging Technology Risks ## STEP 3: DEVELOP APPETITE STATEMENTS For each risk category, create statements that include: ### A. QUALITATIVE DESCRIPTION Example: "The organization has a LOW appetite for risks that could result in unauthorized disclosure of customer financial data, even if the probability is low." ### B. QUANTITATIVE BOUNDARIES Example: "The organization will not accept risks that could result in system unavailability exceeding 4 hours for customer-facing applications." ### C. DECISION GUIDANCE Example statements for Data Breach/Information Disclosure: ### Risk Appetite Statement Example Table | Risk Level | Appetite Statement | Governance Implications | | --- | --- | --- | | LOW | We have minimal tolerance for risks that could result in unauthorized disclosure of sensitive customer data, even if probability is low. | • Requires executive-level approval for any exceptions to data protection controls\n\n• Investments in data protection take priority\n\n• Compensating controls required for all identified vulnerabilities | | MODERATE | We have limited tolerance for risks that could result in unauthorized disclosure of internal business data that is not customer related. | • Exceptions may be approved at director level\n\n• Risk acceptance requires business case\n\n• Compensating controls recommended for vulnerabilities | | HIGH | We accept reasonable risks associated with disclosure of public or marketing information where no regulatory requirements exist. | • Exceptions may be approved at manager level\n\n• Business value may outweigh security concerns\n\n• Baseline controls sufficient | Table 46: Risk Appetite Statement Example ## STEP 4: ALIGN WITH BUSINESS UNITS - Review draft statements with business unit leaders - Validate that statements reflect business priorities - Adjust language for clarity and actionability - Identify potential implementation challenges ## STEP 5: DOCUMENT AND APPROVE - Finalize appetite statements for each risk category - Develop supporting metrics and thresholds - Present to board for approval - Incorporate into security policies and standards ## STEP 6: OPERATIONALIZE AND MONITOR - Communicate approved statements to all stakeholders - Train decision-makers on applying statements - Track decisions against appetite statements - Report deviations to appropriate governance bodies - Review and update statements annually ## IMPLEMENTATION TIPS: - Use consistent language across risk categories to avoid confusion - Balance precision with flexibility - statements should guide decisions without being overly restrictive - Ensure statements address both risk tolerance ("what") and risk appetite ("how much") *** (c)[Kayne McGladrey](https://kaynemcgladrey.com/) - [Get the full book "Cyber Risk is a Myth"](https://www.routledge.com/Cyber-Risk-is-a-Myth-A-Business-Approach-to-Integrated-Risk-Management/McGladrey/p/book/9781041249054)