Risk Treatment

Risk Treatment is making decisions about the best actions to take regarding the identified and prioritized risk. There are four types outlined below:

I’m posting this because it is a concept that I have in the past been confused on. For example, mitigation and transference can be confused in the following way. If someone buys software as a decision are they transferring the risk to the manufacture of the software? No, this is an example if mitigation, because no other outside party has taken responsibility.

I also think that risk avoidance should just be called risk elimination. To me avoidance sounds a lot like taking no action, which is actually risk acceptance. Very strange way to think about it!