StudyToCert

All certifications / CC / Lessons

ISC2 Certified in Cybersecurity 2026 outline · Domain 1: Security principles

Risk assessment (qualitative vs quantitative) and treatment: avoid, mitigate, transfer, accept

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

Risk management is a cycle: identify risks, assess them, decide how to treat them, then monitor and repeat. Assessment tells you how big each risk is so you can spend limited money and time on the ones that matter most. There are two broad ways to assess, and four ways to treat what you find.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 4 more sections, 5 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CC for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CC study plan