Skip to content
atlas

Risk management

The ongoing work of finding, weighing and handling risks so that time and money go where they protect the most.

Draft - this entry has not been reviewed yet.

Read the full article →

Formal

The repeating cycle in which an organisation sets its criteria for acceptable risk, identifies and assesses risks, chooses how to treat each one, and monitors and reviews the result, with leadership accountable for the decisions.

In plain English

Like a household deciding which locks, insurance and smoke alarms are worth paying for, instead of buying everything or nothing.

In practice

Each spring the IT security manager at a small Danish manufacturer goes through the main risks with the managers, updates last year's scores, and the board agrees which ones get a budget first.

Why it matters

No company can protect everything equally, so without it money is spent on the loudest fears rather than the real dangers - and rules such as NIS2 expect leadership to show it is done.

Technical deep dive

ISO 31000:2018 is organised in three layers: principles (clause 4), a framework that embeds risk management in governance, leadership and decision-making (clause 5), and the process of scope and context, assessment, treatment, monitoring and review, communication and consultation, and recording and reporting (clause 6). It is guidance and not certifiable. ISO/IEC 27005:2022 applies the process to information security, and ISO/IEC 27001:2022 makes it auditable: clauses 4.1 and 4.2 establish context and interested parties, 6.1.2 and 6.1.3 define the assessment and treatment processes, 8.2 and 8.3 require them to be run, 9.1 and 9.3 cover measurement and management review, and clause 10 covers improvement. A frequent confusion is clause 6.1.1, which concerns risks and opportunities affecting the management system itself, not the information security risks handled under 6.1.2.

NIST describes the same idea with different vocabulary. SP 800-39 defines four components, framing, assessing, responding to and monitoring risk, across three tiers: organisation, mission or business process, and information system. SP 800-37 Rev. 2 operationalises tier 3 in the Risk Management Framework, and CSF 2.0 (2024) added a Govern function whose risk management strategy category covers appetite, tolerance and integration with enterprise risk management. NIST IR 8286 addresses how cybersecurity risk registers roll up into the enterprise risk register, which is where boards actually compare cyber risk with financial, operational and strategic risk.

Organisationally, responsibilities are commonly described with the Institute of Internal Auditors' Three Lines Model (2020, a revision of the earlier three lines of defence): operational management owns and manages risk, a second-line risk or security function sets methods and challenges, and internal audit gives independent assurance. Risk ownership should sit with the person accountable for the business activity, not with the CISO by default; a register where the security team owns every risk signals that the business has not accepted accountability.

Regulation has turned this from good practice into obligation. NIS2 Art. 21(1) requires appropriate and proportionate technical, operational and organisational measures to manage risks, taking into account exposure, size and the likelihood and severity of incidents, and Art. 20 requires management bodies to approve those measures, oversee their implementation and follow training, with liability for infringements; in Denmark this is implemented through NIS2-loven. DORA imposes a comparable ICT risk management framework on the financial sector. The practical measure of maturity is whether risk ratings actually drive budget and project decisions, rather than a register refreshed once a year for the auditor.

What to learn first

Everything this builds on, foundations first.

  1. CIA triad
  2. →Threat
  3. →Asset
  4. →Vulnerability
  5. →Impact
  6. →Likelihood
  7. →Risk
  8. →Risk management

Relationships

Part of
Governance

Sources & further reading

Standards & official texts

  • ISO/IEC 27005:2022

Course material

  • Cyber Security Fast Track - Ordliste

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Mentioned in

Check yourself

Loading…

Atlas is in beta.