Avoidance (not processing, storing or maintaining the asset) is simply
transferring the risk to whoever has the asset (or to no one if the asset is destroyed,
discarded, or abandoned). Transfer of assets outside the risk area is one way to
mitigate the risk: move the asset to where the risk does not affect it. Reduction of
threat, vulnerability, and criticality/mission impact are all different ways to mitigate risk.
Detection is not, in my opinion, a response to risk all by itself: rather, it is part of a
strategy to respond to a potential threat.18 Recovery, likewise, is part of a strategy to
reduce the impact of a threat (thus mitigating the risk).
Bass and Robichaux’s model is, however, still useful, as it identifies the basic
methods to mitigate risk. Where this study recommends mitigating risk, the specific
Bass & Robichaux method will also be specified.