Purpose: These examples show how broad appetite statements can become measurable boundaries. They must be approved and tailored to actual objectives and obligations.
Illustrative tolerance statements
Critical-service interruptionNo single cyber event should leave a tier-one customer service without an approved manual or alternate operating method for more than four hours.
Privileged accessAdministrative access without multifactor authentication requires documented executive exception, compensating safeguards, and an expiry of no more than 30 days.
Supplier concentrationNo new critical service may rely exclusively on a supplier already supporting more than three tier-one processes without concentration review.
Sensitive-data processingNew external processing of regulated or highly sensitive data requires approved assessment, contract terms, and incident-notification arrangements before launch.
Overdue treatmentHigh residual risks may not remain past their agreed treatment date without renewed acceptance by the accountable executive.
Recovery confidenceCritical systems must have recovery evidence within the approved testing interval; an expired test creates an escalation condition.
Worked examples
| Example | Context / Rating | Condition / Safeguard |
|---|
How to use this page
- Choose a boundary connected to an objective or obligation.
- Make the condition observable with available evidence.
- Assign authority for exceptions.
- Define the action required when the boundary is crossed.
- Review tolerance after incidents, major change, or strategy shifts.
Cautions
- “Zero tolerance” is rarely usable without defining what zero means.
- A threshold that cannot be measured will not guide action.
- Tolerance should not be copied unchanged across every service or data type.
Educational use: Tailor the language and decision authority to the organization. This page is not a certification, legal opinion, security assessment or substitute for professional advice.
Frequently asked questions
Can a small organization use this tool?
Yes. Reduce the number of fields or questions, but retain the scenario, business consequence, accountable owner, decision and review date.
Does this replace professional advice?
No. It is an educational structure. Legal, insurance, compliance, cybersecurity and other professional decisions may require qualified advice.
How often should it be updated?
Update it when the related service, supplier, data, threat conditions, controls, incident history or business priorities change materially.