Risk identification is the foundational step of the risk management lifecycle, focused on building a comprehensive understanding of every threat an organization faces. This coverage walks through the key methods used to surface, document, and begin tracking organizational risks.
Risk Identification
Before we can even analyze risks or overcome risks, we first of all have to identify what the risks are.
Here's the cycle that we're using for risk management, and one of the first steps in this is the identification. What we're doing here is we're identifying what the risks are. What we want to do is get a good understanding of all of the risks that we have to overcome, or at least be aware of.
There are a lot of different ways that we can do risk identification. Really, it's going to be very dependent on what your company is and how it operates, and whatever you need to do to go and identify what those risks are. So there's a lot of activities that could fall into this, identifying what the risks are.
One of the things that I like to start out with is documenting just the known risk. We have a lot of ideas about what the risks are already, to the company and our infrastructure, so just getting those down and starting with that is a good start.
Another thing that I like to do is just take a look at the assets of the company. That can identify where the risks are going to be at, because a lot of times it's the assets that are at stake, it's the assets that we need to be concerned about. So identifying what those assets are can help us identify what the risks are. Assets are those things that just have some sort of value to the company, so it could be anything from money to data to code to reputation. Even things like the employees of the company could be considered an asset.
Once we've identified the assets, then what we would think about is what are the risks to those assets. For instance, if we consider we have a lot of great employees, those great employees could leave the company, and that's a risk — and how do we mitigate that?
Another way to look at that is we could look at that the assets have some sort of threats to them, and so we identify those threats. Here I'm using the CIA, which is confidentiality, integrity and availability. And from there we can look at what the vulnerabilities of each of those threats are. So for confidentiality, here's a lot of different vulnerabilities, or things that can happen that would threaten confidentiality.
I treat vulnerability management as a separate process in security operations. However, there is an overlap between risk management and vulnerability management, and here what we can do is take things like vulnerability scans and pen testing — things that would discover vulnerabilities on our network — and we can include that in our risk assessment.
There are a lot of different assessments and audits that we could carry out to help identify risks. Really any audit or any assessment would do, but some specific ones:
Really any of these assessments would work.
The next one is the interviews. We could conduct interviews with managers, we could conduct interviews with different departments, and we can identify risks that way — whether we're asking them what they view as being risks to the company, or we could be just interviewing them, asking them what software are they using, what assets are they using, what are they using, and ask them guided questions to identify what these risks are.
And questions that we're going to be asking others and ourselves are: what are we afraid of? What could happen in the future that would hurt the business? What has happened in the past that has hurt the business, or what's happened to similar businesses? So these are some of the questions that we could ask ourselves and ask others to identify what these risks are.
Ultimately what we want to do is have a list of all the risks that we have identified for the business, and then we're going to start tracking those. And one way we could track them is a risk register. Essentially it's a way that we can record the risks.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →