TechKnowSurge
NIST CSF GV.RM-01 CompTIA Security+ 1.2 ISC2 CISSP 1.9 NIST NICE K0728 CompTIA Security+ 5.2 NIST CSF GV.RM-03 NIST NICE K0735
VideoSecurityFree

Risk Management Approach

Risk management fundamentals cover the frameworks, models, and lifecycle processes organizations use to identify, assess, and mitigate threats to business assets. Core concepts include Enterprise Risk Management, the People-Processes-Technology model, data states, the CIA triad, and widely adopted frameworks such as NIST, COSO, and ISO 31000.

Complete this video to capture a CTF flag worth 1 point.

About this video

Risk management is a continuous, structured discipline that organizations rely on to understand and reduce threats to their people, processes, data, and technology. At the broadest level, Enterprise Risk Management (ERM) provides a program-wide view of organizational risk, incorporating policies, procedures, services, and data into a cohesive strategy. To analyze risk more precisely, teams apply models such as the People-Processes-Technology (PPT) framework, which examines human factors, operational workflows, and the tools employees use to carry out their roles. Data-centric analysis looks at risk across three states — data in transit, data at rest, and data in use — while the CIA triad of Confidentiality, Integrity, and Availability offers another structured way to ensure all dimensions of information security are addressed. Every risk moves through a lifecycle: it is identified, assessed for depth and potential impact, assigned a control or mitigation action, and then monitored to confirm the response was effective. Controls can be preventive, detective, or restorative, and the process repeats continuously to keep pace with an evolving threat landscape. Prioritization plays a central role, helping organizations determine which risks demand immediate attention and allocate resources accordingly. Widely adopted frameworks from organizations such as NIST, COSO, and ISO provide structured blueprints — each with its own methodology — that teams can use to design and implement a formal risk management program suited to their environment and risk tolerance.

What you'll learn

What's covered

Risk Management Approaches

Aligned to

NIST CSF
GV.RM-01 Risk management objectives are established and agreed to by organizational stakeholders.
GV.RM-03 Organizational risk management results are used to inform cybersecurity risk management and vice versa.
CompTIA Security+
1.2 Summarize fundamental security concepts.
5.2 Explain elements of the risk management process.
ISC2 CISSP
1.9 Understand and apply risk management concepts
NIST NICE
K0728 Knowledge of Confidentiality, Integrity and Availability (CIA) principles and practices
K0735 Knowledge of risk management models and frameworks

Key terms

Enterprise Risk Management
ERM
Enterprise Risk Management is the organization-wide process of identifying, assessing, and prioritizing risks across all business units to minimize the impact of threats on strategic objectives. In cybersecurity, ERM integrates information security risk into the broader corporate risk posture.
People, Processes, and Technology
PPT
The three elements that make up the Cybersecurity Cube's Countermeasures dimension: the human, procedural, and technical elements that must each be evaluated when applying security controls.
CIA Triad
The three core principles of information security: Confidentiality, Integrity, and Availability.
Confidentiality
The principle that information is accessible only to those authorized to access it.
Integrity
The assurance that data has not been tampered with and remains accurate and complete.
Availability
The assurance that systems and data are accessible and operational when needed by authorized users.
Risk Assessment
The process of identifying, analyzing, and evaluating risks to determine their potential impact.
Risk Management
The ongoing process of identifying, assessing, and mitigating risks to an acceptable level.
Data States
The three conditions in which data exists — in transit (being transmitted), at rest (stored), and in use (being processed) — each presenting distinct security risks.
NIST Risk Management Framework
NIST RMF
A risk management framework developed by the National Institute of Standards and Technology that provides a structured process for integrating security and risk management into information systems.
COSO ERM
An enterprise risk management framework developed by the Committee of Sponsoring Organizations of the Treadway Commission that provides guidance for organizations to manage risk across the enterprise.
ISO 31000
An international standard published by the International Organization for Standardization that provides principles and guidelines for effective risk management.

Topics

Risk Management Enterprise Risk Management Cia Triad Nist Rmf Iso 31000 Coso Erm Cybersecurity

Transcript

Enterprise Risk Management

Just like anything, there's a lot of different ways we could approach risk management. We're just going to talk about certain aspects of risk management and the different approaches we could take towards risk management. This isn't going to be something that's in-depth, but we're just going to hit a few high-level topics.

When it comes to the approach to risk management, there's something called Enterprise risk management, or ER, and we have an Enterprise risk management program. This is just that program that's looking at the overall risk to the company. It's taking into consideration our processes and procedures, and we have checklists and all of our policies that go into that, our different services, and different data that's going into that. There's a lot that plays into a whole program and how the program functions.

Different Models for Looking at Risk

When we start taking a deep dive into what are the risks to the business, there are different models that we can use out there, and different approaches and different ways to look at things.

A couple of those that we can take a look at is, first of all, PPT, or people, processes and technology. People, processes and technology is one way that we can start analyzing, okay, what are the risks? Well, we have people that are in place, so what is the risk from a people perspective? And they're carrying out processes, so what is the risk in those processes that we have, and identify weaknesses in those processes and things that need to be improved. And what is the technology that those people are using to carry out their job, to carry out their function? And so we take a look at the technology and the weaknesses to the technology. So that's one way that we can look at all of the weaknesses within our business, or what risks we have to our business.

Or we take a look at something like data and what's happening with data. Well, we're moving it around, so it's in transit, and what's happening to the risk when it's in transit, and what are we putting into place to mitigate that risk? Or what happens when data is at rest, being stored on something? So we have data that's being shipped around and sent around to different places, and what does that look like? And then when it's just sitting there stored on somebody's laptop maybe, or maybe it's on the database server, how are we securing that, how is the security at rest? Or it's got to be processed sometimes, so sometimes we print it out and then we're looking at it and using that information, and is those documents being left out? Or it's being processed on the actual processor of those servers. How is it being utilized, and is there risk to that? So that's another model, or different way that we can look at risk.

There's security models such as confidentiality, integrity and availability, and we look at, okay, well, how are we taking a look at the confidential side of things, how are we looking at the integrity side of things, how are we looking from an availability perspective? So once again, just a different way that we can take an approach to making sure that we're covering all of our bases and looking at all of the risks to the company.

The Risk Life Cycle

Essentially risks have a life cycle to them, and through this life cycle we're going to identify a risk, and from there we have to do an assessment on that risk. And then from there, once we've assessed the risk and fully understand it and know what actions we're going to take, we have to put that action into place, or we call it a control. And a control is something we put into place to mitigate a risk, to lessen a risk, to lessen the probability or lessen the impact that it has. And then what we want to do is we want to review to make sure that in fact what we've done is actually successful. So our risk has a life cycle, and risk management has a life cycle.

During this risk management life cycle, we could put controls into place that would protect some sort of asset, that would guard it from something happening to it. Or to detect, if something does happen to it, that we can actually detect that something has happened to it. And take a response, so we can respond to it if something were to happen to it. Or to restore it, if maybe something was deleted, that we could actually do a restore on that data, or whatever the asset is.

Risk Management Frameworks

When it comes to risk management and risk management life cycles and our approaches, there are different frameworks. A framework is just something that's set up. I like to think of it as a blueprint, a blueprint of how we could be operating. And there's several risk management frameworks out there that we could go and grab this blueprint and then set up our risk management program based off of that risk management framework.

Here's some examples of risk management frameworks. NIST has their nisk risk management framework, and properly named there. The COO, or COSO, has the ERM framework. And then the ISO 31000 risk management is another framework. So these are different frameworks from different organizations that we could use out there for setting up our risk management program.

A Generic Risk Management Process

Now, depending on which risk management program you're going to use, it could look very different on how you implement those frameworks and what they look like. But I've come up with kind of a generic one, a risk management process here that's just a generic one that takes a few different ones and adds them together.

So one of the things that we need to do is we need to establish our risk tolerance. How much risk are we willing to take on as a company? And from there we go through this risk process and do a risk assessment to identify the different risks that are within our network, within our different infrastructure, risks to the business. And then what we're going to do is we're going to analyze those risks, do an analysis on it to determine what is those risks, how deep do they go, and what would be some mitigation steps that we could take to fix that.

And essentially what we're going to do is we're going to start prioritizing those risks. And I like to think of the analysis and the prioritization kind of happening at the same time. There's kind of some back and forth that happens there to really prioritize which risks that we should fix and which ones we should tackle first. And then from there we're going to create some sort of plan, and then we'll implement that plan for the mitigation, so there's going to be a mitigation part of this. And then from there we're going to go into monitoring and seeing if this has been resolved. And this is a continuous cycle, that whether it's been resolved or not, then we go through the identification process again, and we continually do this on our network.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →