TechKnowSurge
NIST CSF GV.RM-06 NIST 800-53 RA-3 CompTIA Security+ 5.2 ISC2 CISSP 1.9 NIST CSF ID.RA-06 NIST 800-53 PM-9 CompTIA SecurityX 1.3
VideoSecurityFree

Risk Tracking & Risk Register

A risk register is a structured tool used to track organizational risks through their full lifecycle, from identification and assessment to mitigation and review. Each recorded risk is assigned an owner, evaluated by likelihood and impact, and linked to a treatment or response.

Complete this video to capture a CTF flag worth 1 point.

About this video

Risk management is not a single action but an ongoing process with a defined lifecycle. Once a risk is identified, it moves through assessment, control implementation, and a review phase to confirm whether mitigation efforts have been effective, whether the risk has been reduced or fully eliminated. Maintaining visibility across all of these stages requires a systematic tracking mechanism, and the risk register is the standard tool used for that purpose. It can take many forms, from a simple spreadsheet to a more complex database, depending on the scale and complexity of the organization's risk environment. A risk register centralizes all identified risks and records the relevant details needed to manage them effectively. One of the most important fields is the risk owner, the individual assigned accountability for shepherding a specific risk through assessment and mitigation. Risks are also evaluated based on likelihood and impact, producing a prioritized view that helps organizations focus resources on the threats that pose the greatest danger. The register also captures the chosen treatment or response, providing a clear record of what action was taken and creating the foundation for the review that follows. While a basic risk register may include only a handful of fields, real-world implementations often expand to accommodate additional organizational requirements.

What you'll learn

What's covered

Risk Register & Management

Aligned to

NIST CSF
GV.RM-06 A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated.
ID.RA-06 Risk responses are chosen, prioritized, planned, tracked, and communicated.
NIST 800-53
RA-3 Risk Assessment
PM-9 Risk Management Strategy
CompTIA Security+
5.2 Explain elements of the risk management process.
ISC2 CISSP
1.9 Understand and apply risk management concepts
CompTIA SecurityX
1.3 Explain the importance of risk management for an enterprise.

Key terms

Risk
The potential for loss or harm resulting from a threat exploiting a vulnerability.
Risk Assessment
The process of identifying, analyzing, and evaluating risks to determine their potential impact.
Risk Management
The ongoing process of identifying, assessing, and mitigating risks to an acceptable level.
Risk Register
A centralized document or database that tracks identified risks, their likelihood, potential impact, assigned owners, and planned response actions. The risk register is a core artifact of an organization's risk management program.
Risk Owner
The individual accountable for monitoring and managing a specific risk through its assessment, treatment, and review process.
Risk Treatment
The selected response or control implemented to mitigate, transfer, accept, or eliminate an identified risk.

Topics

Risk Register Risk Management Risk Assessment Risk Treatment Risk Lifecycle Governance Risk Compliance

Transcript

Once we've identified a risk, we're going to want to start figuring out what actions we want to take against that risk. So what we're going to want to do is track the process around a risk of mitigating these risks, and we might want to use a risk register.

Risk to the company has a life cycle. That is a beginning, middle, and maybe sometimes an end. That is, we need to identify these risks, we're going to go through the assessment process, we're going to implement something that will control a specific risk, and then we'll review to see if we have in fact mitigated that risk, whether we reduced it or we've eliminated it altogether.

The risk register

One way of tracking a risk is through a risk register. This could be something as simple as a spreadsheet that you're using to do this, or it could be more complex like a database. Either way, what we'd want to do is we would want to record all of the risks that we have and start tracking them through this process.

The risk owner

One of the things that we may want to track is a risk owner. The risk owner is going to be the one that's responsible for that risk. When it's identified, they're going to go through possibly the assessment process and the mitigation process, or is going to see that through, that's going to take accountability for what happens to that risk.

Evaluating and treating the risk

Now we could end up with a long list of risks, and some of those are going to be more important to address than others, so we're going to need to start evaluating these risks. Well, we evaluate it on the likelihood and impact. Essentially it's going to be a measurement of that risk, so that way we understand which risk is the most prevalent, which risk needs to be addressed first.

Then there's going to be some sort of solution that we implement, or risk treatment, or something that we're going to go through to mitigate this risk, a response to it.

This is just a simple example of a risk register, but you could have a lot of fields to this. There could be a lot of things that you're tracking, but this is a real basic one.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →