Risk management is the systematic handling of security risk: risks are identified, assessed, treated and monitored. The aim is not to eliminate every risk but to decide deliberately which ones are carried.
At a glance
The aim is a deliberate decision, not the absence of risk.
Without an owner, a risk stays untreated.
A risk register with no dates is a wish list.
Risk management replaces gut feeling with a decision you can retrace. Protecting everything equally means protecting nothing well enough.
Identify, assess, treat
Identify what can go wrong. Assess it by likelihood and impact. Treat it by avoiding, reducing, transferring or deliberately carrying it – and monitor the outcome, because the situation changes.
Real-world examples
- An availability risk is carried deliberately, because insuring it would cost more than the expected loss.
- A supplier risk is transferred contractually and tracked in the register with a review date.
Common misconception
Myth “Risk management means eliminating all risk.”
Reality It means knowing which risks you carry – and making that choice deliberately and traceably.
Frequently asked questions
How often should a risk register be reviewed?
At least annually, and always after significant change. The NIST Risk Management Framework describes a proven approach.
Does risk management need certification?
No, but a management system to ISO 27001 gives the approach an audited structure.