Risk Identification and Risk Register
Identify organizational assets, threats, and vulnerabilities, then document risks in a structured register with likelihood and impact ratings.
What Is Risk in Security?
Risk is the potential for loss or harm resulting from a threat exploiting a vulnerability. In information security, risk is expressed as the combination of likelihood (how probable the event is) and impact (how severe the damage would be). Understanding risk allows organizations to make informed, cost-effective security decisions rather than trying to eliminate every possible threat.
Assets, Threats, and Vulnerabilities
Risk identification begins with three core elements. An asset is anything of value — servers, databases, intellectual property, or reputation. A threat is any potential event that could harm an asset, such as a ransomware attack or a disgruntled employee. A vulnerability is a weakness that a threat can exploit, such as an unpatched system or weak password policy. Risk exists where threats meet unprotected assets.
All lessons in this course
- Risk Identification and Risk Register
- Qualitative vs Quantitative Risk Analysis
- Risk Treatment: Accept, Transfer, Mitigate, Avoid
- NIST RMF, ISO 27001, and CIS Controls