What factors might determine which traditional method for treating risk (reduce, transfer, avoid, redistribute, and accept) would be the most appropriate to take in order to appropriately manage identified risk?

What factors might determine which traditional method for treating risk (reduce, transfer, avoid, redistribute, and accept) would be the most appropriate to take in order to appropriately manage identified risk? What are the three distinct stages found within the ISO 31000 Risk Management process and what are some example of how the security manager would carry each out?

The post should be at least 350 words. Please use the links below as sources. APA format.

Security Science : The Theory and Practice of Security – Chapter 3

https://web-a-ebscohost-com.ezproxy1.apus.edu/ehost/ebookviewer/ebook?sid=976413fc-2afe-4357-830f-602fa3e51449%40sessionmgr4007&ppid=pp_51&vid=0&format=EB

Strategic Security Management : A Risk Assessment Guide for Decision Makers – Chapters 3, 5, and 6

https://ebookcentral.proquest.com/lib/apus/reader.action?docID=282098&ppg=51&tm=1530212805421