Whatever risk is left once mitigation has been applied. The IT governance framework has to approve it (with corporate governance involved when the business must accept it), and Phase G keeps it under watch.
Read more: TOGAF Standard
In the Ultra Transcenders books
Each book explains Residual risk in context, with comparison tables and the common traps.
Terms in this definition
- Risk
As ISO 31000 puts it, how uncertainty affects objectives; that effect can be good or bad.
- Governance
Keeping cloud deployments in line with an organisation's rules on technology, security and compliance, helped by Azure Policy, tags and resource locks.