TechKnowSurge
NIST NICE K0721 NIST CSF GV.RM-06 CompTIA Security+ 5.2 ISC2 CISSP 1.9 NIST CSF ID.RA-05 NIST 800-53 RA-3 CompTIA SecurityX 1.2 NIST NICE K0835
VideoSecurityFree

Risk Management

Cybersecurity risk management centers on two core activities: establishing a measurement framework and conducting structured risk assessments. Together, these allow organizations to identify, prioritize, and respond to threats in proportion to their risk tolerance and available resources.

Complete this video to capture a CTF flag worth 1 point.

About this video

Cybersecurity risk management is not a single activity but a structured function with two distinct components: establishing a measurement framework and executing recurring risk assessments. The measurement component requires choosing a model that fits the organization's resources and business context. At its simplest, this means using qualitative scales — rating probability as rare, unlikely, possible, likely, or certain, and rating impact from negligible to severe. A more rigorous approach assigns numerical values, expressing probability as a percentage and impact as a financial cost, which produces a concrete dollar figure for each risk. The right model depends on organizational capacity, but in either case the goal is to create a consistent standard against which all risks can be evaluated. Alongside the measurement model, organizations must define their risk tolerance — the degree of exposure they are willing to accept — which varies considerably between an early-stage company prioritizing speed and a mature enterprise with significant assets to protect. Once a measurement framework is in place, formal risk assessments can be conducted on a recurring basis, typically annually. These assessments follow a defined process: confirming that the risk tolerance and measurement model remain accurate, identifying risks across all areas of the business, analyzing and prioritizing those risks by their potential impact, planning and executing mitigation activities, and then monitoring outcomes to evaluate effectiveness. The deliverable is a comprehensive risk assessment report presented to organizational leadership, providing visibility into the company's threat landscape and supporting decisions about where to invest in security controls. Supporting tools such as a risk register document each identified risk alongside its owner and relevant details, and response strategies — including avoiding, reducing, or transferring risk — are selected based on the organization's priorities and tolerance levels.

What you'll learn

Aligned to

NIST NICE
K0721 Knowledge of risk management principles and practices
K0835 Knowledge of risk assessment principles and practices
NIST CSF
GV.RM-06 A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated.
ID.RA-05 Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization.
CompTIA Security+
5.2 Explain elements of the risk management process.
ISC2 CISSP
1.9 Understand and apply risk management concepts
NIST 800-53
RA-3 Risk Assessment
CompTIA SecurityX
1.2 Given a scenario, implement the appropriate risk management strategies, policies, and controls.

Key terms

Risk
The potential for loss or harm resulting from a threat exploiting a vulnerability.
Risk Management
The ongoing process of identifying, assessing, and mitigating risks to an acceptable level.
Risk Assessment
The process of identifying, analyzing, and evaluating risks to determine their potential impact.
Probability
The likelihood that a specific threat event will occur, expressed as a qualitative rating or percentage.
Impact
The potential consequence or damage to an organization if a risk event occurs, expressed qualitatively or as a monetary value.
Risk Register
A centralized document or database that tracks identified risks, their likelihood, potential impact, assigned owners, and planned response actions. The risk register is a core artifact of an organization's risk management program.
Risk Tolerance
The level of risk an organization is willing to accept before taking action to reduce or eliminate it. Risk tolerance is determined by leadership and reflects the organization's risk appetite, regulatory environment, and available resources.

Topics

Risk Management Risk Assessment Risk Register Threat Identification Cybersecurity

Transcript

A cyber security program is all about managing risk. However, there are some specific steps that we need to take in managing risk.

Each one of these functions is what I've already outlined as being part of a cyber security program, and you could take any one of these functions and argue that it is risk management. So what do I mean by risk management, and what does this function look like?

Two sub-routines: measurement and assessment

When it comes to risk management I break it into two different objectives — or, since we're thinking of risk management as being a function, I like to think of it as breaking it into two different sub-routines. Number one is measurement, or creating the measurement that we're going to measure everything else against. Second is the risk assessment piece of this.

Measurement

Let's first tackle the measurement side of this. Risk has an equation, and that equation is probability times impact equals our risk.

Depending on how much resources we have and how in depth we want to go with measuring risk, we might choose different routes in measuring what our risk is. For instance, in this example right here, probability we could just measure by rare, unlikely, possible, likely or certain, and then we would just assess what we feel like this would be at. And the impact: negligible, minor, moderate, major or severe — once again we would choose what level we would feel like that was at.

Or I could actually get some numbers involved in this. Probability would be a percent, the likeliness that something would happen, and the impact would be more the dollar amount of the impact if it were to happen. Then we actually have dollar amounts associated with risk, and this is obviously more ideal, actually having a dollar amount of the cost of that risk. However, there's a lot more that has to go into figuring those numbers out, so it can be a lot more resource intensive to figure out those numbers.

The first step really is to choose what model we're going to use, based off of the business needs and how much resources we have, and then start putting some boundaries around it on how we're going to label these different risks.

Risk tolerance

Another thing that needs to happen is some sort of assessment on what the business risk tolerance is. There are some businesses that are just starting up and there's not a lot of assets that need to be protected right from the beginning, plus we need to be really agile, so we're willing to take more risks to move forward quickly. The flip side of that is that we may be a more established business with lots of assets that we need to protect and not be willing to take as big of risks, so we're willing to spend more money on mitigating those risks than a company that wants to be more agile.

As an example, in our vendor and supply chain management we want to assess the risk of a new vendor. If we were bringing on a new vendor we would assess the risk of that vendor. What we have now is a measurement to measure against, to see what the risk is of that vendor.

Risk assessment

That brings us to the risk assessment. Although each of these functions could have an element of risk assessment in it, what I'm really talking about is a separate risk assessment — a separate risk assessment that's done on some sort of recurring basis, maybe on an annual basis. What would be generated out of it is some sort of report, a risk assessment report, that would then be reported to the leadership so they understand the risk involved in the company. It also would help you get resources to mitigate those risks, and then set out tasks and projects so that way you can mitigate risk within the company.

This risk assessment would have its own process. Once again, you would establish the risk tolerance of the business and make sure that the model is still accurate. You would go into identifying what risks there are to the company, analyze those risks, prioritize those lists based off of what the impact would be to the company or what the risk is to the company, plan to mitigate those risks, go through a mitigation process, and then monitor to see if it was effective or not.

The risk assessment is very comprehensive in nature, so you're going to look at all aspects of the company and do many different types of assessments on the company, and that's all going into this risk assessment report.

You also may utilize things like a risk register, where you would document the risk, who is the owner of the risk, and some details around those risks. Then we would want to choose how we're going to respond to that risk — whether we avoid the risk, reduce the impact of that risk somehow, or transfer the risk.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →