Security Risk Management
Security risk management is the discipline of identifying what could harm an organization's information systems, judging how likely and how damaging each threat could be, and deciding what to do about it. It turns security spending into justified decisions grounded in threats, vulnerabilities, and business impact.
itCybersecurity fundamentals and governance | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Don't Panic — Security Risk Management
Security risk management is the work of deciding which bad outcomes matter enough to change something. Security can produce a magnificent heap of findings, warnings, and colored boxes. The heap is not a decision. Risk management turns it into one by asking what could happen, how likely it is, how much harm it causes, and who can accept what remains.
The first useful distinction is between a threat source, a threat event, and a vulnerability. The threat source is the actor or circumstance capable of harm. The event is what happens. The vulnerability is the weakness it can use. Add impact, and the picture becomes assessable. An unpatched service is not automatically a crisis; it needs a route to the weakness and a consequence worth protecting against. This is less cinematic than shouting “critical,” but considerably more helpful.
Before scoring, set the frame. Risk appetite is the kind and amount of risk an organization is willing to take to pursue its objectives. Risk tolerance is the boundary it will not cross. Without those rules, two careful people can look at the same evidence and produce different ratings, each accompanied by a very convincing spreadsheet. The spreadsheet has done nothing wrong. It was merely asked to settle a policy decision.
The loop is compact: frame, assess, respond, monitor, then revise. Assessment identifies the event and its conditions, estimates likelihood and impact, and decides whether the exposure is acceptable. Response avoids, reduces, transfers, or accepts the exposure. The figure that matters afterward is residual risk: what remains after controls and responses, not the busy calendar of activities surrounding them.
A risk register holds the result. Its job is to connect a risk statement to an owner, a response, evidence, and a review date, then let those entries roll up into enterprise decisions. It is not a trophy case for every security concern ever observed. A control lowers residual exposure only when evidence shows that it changed likelihood or impact. That is an annoying standard, which is why it is valuable.
Read the intro for the full loop and the relationship between risk, threat events, and controls. Use the slides to see the decisions and tiers at a glance. Keep the cheatsheet nearby when defining scales, register fields, and response options. The quiz checks whether the vocabulary still holds together once the reassuring diagrams have left the room.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://csrc.nist.gov/pubs/sp/800/30/r1/final
Supports
- Risk as a function of likelihood of threat events and magnitude of impact
- Threat sources, threat events, vulnerabilities, and predisposing conditions
- Prepare, conduct, and maintain as the assessment process
- Determining likelihood and impact and determining risk
- Qualitative and quantitative assessment approaches
- Risk response options and residual risk
- Correlated and aggregated risk analysis
- https://csrc.nist.gov/pubs/sp/800/39/final
Supports
- Risk framing with assumptions, constraints, tolerance, and priorities
- Tier 1 organization, Tier 2 mission/business process, and Tier 3 information system levels
- Risk management as an ongoing multi-tier process
- https://csrc.nist.gov/pubs/sp/800/37/r2/final
Supports
- Risk Management Framework system life-cycle process
- Risk acceptance and authorization by senior officials
- Security and privacy integration in risk decisions
- https://www.iso.org/standard/80585.html
Supports
- ISO/IEC 27005:2022 guidance on managing information security risks
- Risk identification, risk analysis, risk evaluation, and risk treatment
- Supporting ISO/IEC 27001 requirements on addressing information security risks
- October 2022 fourth-edition publication
- https://csrc.nist.gov/pubs/ir/8286/r1/final
Supports
- Integrating cybersecurity risk into enterprise risk management
- Cybersecurity risk register as the organizing construct
- Expressing and aggregating cyber risk in business and enterprise risk language
- Risk statements, likelihood, impact, owners, and responses in register entries
- https://csrc.nist.gov/pubs/ir/8286/final
Supports
- October 2020 final publication of the original IR 8286
- Cybersecurity risk as an input to enterprise risk management processes
- https://csrc.nist.gov/pubs/ir/8286/a/r1/final
Supports
- Practical guidance for building and using a cybersecurity risk register
- Getting started with enterprise cybersecurity risk management
- https://csrc.nist.gov/pubs/cswp/29/the-nist-cybersecurity-framework-csf-20/final
Supports
- CSF 2.0 functions including Govern and Identify
- Cybersecurity risk governance, strategy, and assessment outcomes
- February 26, 2024 publication of CSF 2.0
- https://publications.opengroup.org/standards/open-fair-standards
Supports
- Open FAIR Body of Knowledge and its O-RA and O-RT standards
- Loss frequency, loss magnitude, and loss exposure
- Quantitative information security risk analysis
- https://publications.opengroup.org/c13g
Supports
- October 2013 publication of the Risk Analysis (O-RA) Standard version 1.0
- FAIR-based risk analysis scenarios
- https://csrc.nist.gov/nist-cyber-history/risk-management/chapter
Supports
- FIPS 65 in 1979 as early risk analysis guidance
- Original NIST SP 800-30 in 2002
- FISMA enactment through the E-Government Act of 2002
- Original NIST SP 800-37 in 2004
- SP 800-37 Revision 1 introducing the Risk Management Framework in 2010
- SP 800-39 in 2011 and SP 800-30 Revision 1 in 2012
- SP 800-37 Revision 2 in 2018
- https://www.nist.gov/publications/risk-management-guide-information-technology-systems
Supports
- July 2002 publication of the original NIST SP 800-30
- Risk management methodologies for information technology systems
- https://www.iso.org/standard/65694.html
Supports
- ISO 31000:2018 risk management guidelines
- Supersession of the earlier 2009 edition
- https://www.nist.gov/news-events/news/2014/02/nist-releases-cybersecurity-framework-version-10
Supports
- February 12, 2014 release of the Cybersecurity Framework Version 1.0
- Framework Core functions Identify, Protect, Detect, Respond, and Recover
- Voluntary, risk-based framework for managing cyber risk
- https://csrc.nist.gov/projects/risk-management
Supports
- NIST risk management project as the canonical hub for risk guidance
- https://github.com/Arudjreis/awesome-security-GRC
Supports
- Discovery of CISO Assistant, riskquant, minimalist-risk-management, Comply, Mozilla RRA, OCTAVE, FAIR Institute, and COSO as GRC ecosystem resources
- Awesome Links curation decision for security risk management tooling
- https://ciso-assistant.com/
Supports
- Open-source GRC platform combining governance, risk assessment, compliance, and audit reporting
- https://github.com/Netflix-Skunkworks/riskquant
Supports
- Python library for risk quantification with annualized loss and loss exceedance curves
- https://github.com/magoo/minimalist-risk-management
Supports
- Lightweight risk management program documentation
- https://github.com/strongdm/comply
Supports
- SOC 2-focused compliance automation with policy generation and ticketing integration
- https://infosec.mozilla.org/guidelines/risk/rapid_risk_assessment.html
Supports
- Mozilla Rapid Risk Assessment methodology for structured risk decisions in limited time
- https://www.cert.org/octave/
Supports
- OCTAVE risk evaluation method developed by the Software Engineering Institute
- https://www.fairinstitute.org/
Supports
- FAIR community and model for quantitative information risk analysis
- https://www.coso.org
Supports
- COSO ERM framework for enterprise risk management
- https://safe.security/
Supports
- AI-driven cyber risk quantification and management platform built on FAIR
- https://www.kovrr.com/
Supports
- Probabilistic cyber risk modeling and quantification
- https://www.axio.com/
Supports
- Cyber risk quantification and resilience planning
- https://www.bitsight.com/
Supports
- Security ratings from external observation for third-party and enterprise risk
- https://www.securityscorecard.com/
Supports
- Security ratings and third-party risk monitoring
- https://www.upguard.com/
Supports
- Third-party and vendor risk management with breach-risk scoring
- https://www.vanta.com/
Supports
- Automated compliance and security risk management for small and mid-market teams
- https://drata.com/
Supports
- Continuous compliance monitoring and evidence collection
- https://secureframe.com/
Supports
- Automated compliance management and control monitoring
- https://www.tugboatlogic.com/
Supports
- GRC and risk assessment platform for smaller security teams
- https://www.processunity.com/
Supports
- Third-party risk management platform for vendor assessment and monitoring
- https://www.prevalent.net/
Supports
- Third-party risk management with vendor questionnaires and monitoring
- https://eramba.org/
Supports
- Open-source GRC platform with risk register and framework mapping
- https://infosec.mozilla.org/guidelines/risk/rapid_risk_assessment.html
Supports
- Mozilla operational guidance for a rapid, service-based risk assessment
- A rapid assessment focuses on impact, data, and threat scenarios rather than a complete control review
- Large services with distinct ownership can require separate assessments
- Data flow diagrams, data classification, and accountable service owners as assessment inputs
- https://github.blog/security/application-security/how-github-used-secret-scanning-to-reach-inbox-zero/
Supports
- GitHub operational lessons on validating findings, durable ownership, remediation routing, and residual-risk decisions
- Raw alert counts can contain substantial noise and must be validated before prioritization
- Security remediation at scale requires ownership, disposition context, and a repeatable workflow
