TechKnowSurge
NIST CSF ID.RA-03 NIST 800-53 RA-3 CompTIA Security+ 5.2 ISC2 CISSP 1.9 NIST CSF ID.RA-04 NIST CSF ID.RA-05 ISC2 CISSP 1.10
VideoSecurityFree

Risk Identification

Risk identification is the foundational step of the risk management lifecycle, focused on building a comprehensive understanding of every threat an organization faces. This coverage walks through the key methods used to surface, document, and begin tracking organizational risks.

Complete this video to capture a CTF flag worth 1 point.

About this video

Risk identification is the foundational phase of the risk management lifecycle, and no meaningful analysis or mitigation can take place without it. The goal is to develop a thorough, structured understanding of every risk the organization faces, which requires drawing on multiple sources of information and applying several complementary techniques. The approach varies depending on the nature and operations of the organization, but the underlying objective remains consistent: produce a complete and accurate picture of what is at stake and what could go wrong. A practical starting point is documenting risks that are already known, capturing institutional knowledge before moving on to more systematic discovery methods. Inventorying company assets is another essential early step, since assets — spanning financial resources, data, proprietary code, organizational reputation, and human capital — represent what threats ultimately target. Once assets are identified, the threats against them can be mapped using the CIA triad framework, examining risks to confidentiality, integrity, and availability, and then drilling into the specific vulnerabilities associated with each threat category. Technical activities such as vulnerability scanning and penetration testing contribute directly to this process and represent a natural overlap between risk management and vulnerability management disciplines. Beyond technical assessments, risk identification benefits from structured audits and evaluations including gap analyses, operational reviews, backup and recovery assessments, software and services inventories, network assessments, and compliance reviews. Stakeholder interviews — conducted with managers and personnel across departments — surface risks that technical scans may miss, using guided questions about past incidents, potential future threats, and practices at similar organizations. All identified risks are ultimately compiled into a risk register, a living record that supports ongoing tracking, prioritization, and response planning throughout the risk management process.

What you'll learn

What's covered

Risk Identification

Aligned to

NIST CSF
ID.RA-03 Internal and external threats to the organization are identified and recorded.
ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded.
ID.RA-05 Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization.
NIST 800-53
RA-3 Risk Assessment
CompTIA Security+
5.2 Explain elements of the risk management process.
ISC2 CISSP
1.9 Understand and apply risk management concepts
1.10 Understand and apply threat modeling concepts and methodologies

Key terms

Risk
The potential for loss or harm resulting from a threat exploiting a vulnerability.
Risk Management
The ongoing process of identifying, assessing, and mitigating risks to an acceptable level.
Asset
Any resource of value to an organization, including hardware, software, data, and personnel.
Threat
Any potential event or action that could cause harm to a system, network, or organization.
Vulnerability
A weakness in a system, application, or process that can be exploited by a threat actor.
CIA Triad
The three core principles of information security: Confidentiality, Integrity, and Availability.
Vulnerability Assessment
The process of identifying, quantifying, and prioritizing vulnerabilities in a system.
Penetration Testing
An authorized simulated attack on a system to identify and evaluate security vulnerabilities.
Risk Register
A centralized document or database that tracks identified risks, their likelihood, potential impact, assigned owners, and planned response actions. The risk register is a core artifact of an organization's risk management program.

Topics

Risk Identification Risk Management Threat Modeling Vulnerability Assessment Cybersecurity Risk

Transcript

Identifying the Risks

Before we can even analyze risks or overcome risks, we first of all have to identify what the risks are.

Here's the cycle that we're using for risk management, and one of the first steps in this is the identification. What we're doing here is we're identifying what the risks are. What we want to do is get a good understanding of all of the risks that we have to overcome, or at least be aware of.

There are a lot of different ways that we can do risk identification. Really, it's going to be very dependent on what your company is and how it operates, and whatever you need to do to go and identify what those risks are. So there's a lot of activities that could fall into this, identifying what the risks are.

Start With Known Risks and Assets

One of the things that I like to start out with is documenting just the known risk. We have a lot of ideas about what the risks are already, to the company and our infrastructure, so just getting those down and starting with that is a good start.

Another thing that I like to do is just take a look at the assets of the company. That can identify where the risks are going to be at, because a lot of times it's the assets that are at stake, it's the assets that we need to be concerned about. So identifying what those assets are can help us identify what the risks are. Assets are those things that just have some sort of value to the company, so it could be anything from money to data to code to reputation. Even things like the employees of the company could be considered an asset.

Once we've identified the assets, then what we would think about is what are the risks to those assets. For instance, if we consider we have a lot of great employees, those great employees could leave the company, and that's a risk — and how do we mitigate that?

Threats and Vulnerabilities

Another way to look at that is we could look at that the assets have some sort of threats to them, and so we identify those threats. Here I'm using the CIA, which is confidentiality, integrity and availability. And from there we can look at what the vulnerabilities of each of those threats are. So for confidentiality, here's a lot of different vulnerabilities, or things that can happen that would threaten confidentiality.

I treat vulnerability management as a separate process in security operations. However, there is an overlap between risk management and vulnerability management, and here what we can do is take things like vulnerability scans and pen testing — things that would discover vulnerabilities on our network — and we can include that in our risk assessment.

Assessments and Audits

There are a lot of different assessments and audits that we could carry out to help identify risks. Really any audit or any assessment would do, but some specific ones:

  • A gap analysis — what is the difference between our standards or compliance and what we're actually doing?
  • An operational assessment, to see what operations look like
  • A backup and recovery assessment
  • A software and services assessment
  • A network assessment
  • A compliance and regulation assessment

Really any of these assessments would work.

Interviews and Questions

The next one is the interviews. We could conduct interviews with managers, we could conduct interviews with different departments, and we can identify risks that way — whether we're asking them what they view as being risks to the company, or we could be just interviewing them, asking them what software are they using, what assets are they using, what are they using, and ask them guided questions to identify what these risks are.

And questions that we're going to be asking others and ourselves are: what are we afraid of? What could happen in the future that would hurt the business? What has happened in the past that has hurt the business, or what's happened to similar businesses? So these are some of the questions that we could ask ourselves and ask others to identify what these risks are.

Tracking What You Find

Ultimately what we want to do is have a list of all the risks that we have identified for the business, and then we're going to start tracking those. And one way we could track them is a risk register. Essentially it's a way that we can record the risks.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →