These four terms-avoidance, acceptance, mitigation, and transfer-are strategies used in risk management. From Andrew Ramdayal's guide: "Risk in security refers to the potential for loss, damage, or destruction of assets or data due to a threat exploiting a vulnerability. Risk management strategies include avoidance, acceptance, mitigation, and transfer."