TechKnowSurge
NIST NICE K1076 NIST CSF GV.RM-06 NIST 800-53 RA-3 CompTIA Security+ 5.2 NIST CSF ID.RA-05 ISC2 CISSP 1.9 CompTIA SecurityX 1.3
VideoSecurityFree

DEMO: Risk Register and Analysis

A risk register is a structured tool used to document, assess, and prioritize organizational risks by evaluating each risk's probability and potential impact. This content walks through a practical example of how entries are built, scored, and compared to support informed risk management decisions.

Complete this video to capture a CTF flag worth 1 point.

About this video

A risk register is a foundational document in any organization's risk management program, providing a centralized record of identified risks along with the information needed to evaluate and act on them. Each entry typically includes a unique risk identifier, a linked asset ID, and a designated risk owner — the individual or team accountable for monitoring and responding to that risk. Standardized rating scales for probability, ranging from rare to almost certain, and for impact, ranging from negligible to severe, allow assessors to score each risk consistently and objectively. Once probability and impact scores are assigned, the register calculates a composite risk level and expresses it as a weighted factor relative to all other risks in the register. This relative weighting is critical because it moves the conversation beyond raw scores and highlights which risks represent the greatest exposure compared to everything else the organization is tracking. A concrete example — an unencrypted laptop containing sensitive data stored in a publicly accessible area — demonstrates how a high probability score combined with a severe potential impact can push a risk to the top of the priority list. The risk register also supports documentation of the specific concerns driving each assessment, creating an auditable rationale for how risks were evaluated and ranked. This prioritized, evidence-based view gives security teams, risk managers, and organizational leadership the clarity needed to allocate remediation efforts where they will have the greatest effect.

What you'll learn

What's covered

Risk Register & Analysis

Aligned to

NIST NICE
K1076 Knowledge of risk scoring principles and practices
NIST CSF
GV.RM-06 A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated.
ID.RA-05 Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization.
NIST 800-53
RA-3 Risk Assessment
CompTIA Security+
5.2 Explain elements of the risk management process.
ISC2 CISSP
1.9 Understand and apply risk management concepts
CompTIA SecurityX
1.3 Explain the importance of risk management for an enterprise.

Key terms

Risk
The potential for loss or harm resulting from a threat exploiting a vulnerability.
Risk Assessment
The process of identifying, analyzing, and evaluating risks to determine their potential impact.
Risk Management
The ongoing process of identifying, assessing, and mitigating risks to an acceptable level.
Asset
Any resource of value to an organization, including hardware, software, data, and personnel.
Risk Register
A centralized document or database that tracks identified risks, their likelihood, potential impact, assigned owners, and planned response actions. The risk register is a core artifact of an organization's risk management program.
Risk Probability
A rating that estimates the likelihood of a risk event occurring, often scaled from rare to near-certain.
Risk Impact
A rating that estimates the potential severity of harm if a risk event occurs, often scaled from negligible to severe.
Risk Score
A calculated value derived from multiplying or combining probability and impact ratings to quantify the overall level of a risk.
Weighted Risk Comparison
A method of normalizing risk scores across multiple identified risks to prioritize which risks require the most immediate attention.

Topics

Risk Register Risk Assessment Risk Management Risk Scoring Cybersecurity Governance

Transcript

A Basic Risk Register

This risk register is a real basic one, but this gives us a viewpoint into what a risk register looks like and how we can start doing an assessment on something.

For instance, let's say we have risks. I just put down a few different risks, and I just put generic names in here, but maybe this could be better named. Maybe I have the risk of an unencrypted hard drive — that's the risk that we have — and maybe I could even specify the specific asset. I've got these asset IDs, so maybe I have some way of tracking all my assets, so I track the asset ID of this, and then the risk ID of this. So maybe this is risk ID one, I've just put in here. So we've got some sort of risk ID, so I can reference this on other worksheets. And I'm going to give it some sort of risk owner here.

Scoring the Risk

Now I want to do an assessment on it. This is a drop-down list where I can rate the probability of it. The way I've got these written out, there's a lookup column here, so in the lookup the probability is going to be rare, unlikely, possible, likely and uncertainty. So I've got these different ratings here. And then the impact — what's the impact going to be? The impact is going to be negligible, minor, moderate, major or severe. So I've got these, and then I can select them, and as I change these values it actually changes the values over here.

So maybe this one — the reason why I'm concerned about this is maybe it's on a laptop that has some sensitive data on it and it's unencrypted, and I'm concerned about it being stolen. So what is the probability? Well, maybe it's in a high-risk level area, so I'm going to put four on there. And the impact would be pretty devastating, so maybe I put five. So then this is the risk level there, and this is the factor out of one, so this is really high. This is kind of crazy. And then it compares — this is a weighting of all of the other risks that we've categorized — so this gives us a good idea of what this risk is compared to everything else.

And then I can put in what my top concerns are, and this is because this is unencrypted and in a public area, or whatever the case may be. So there's quite a few things that I mentioned: it's unencrypted, in a public area, and so there's a fear of it being stolen. So now, at some point in time I want to come up with a solution for that, and we'll talk about that later on.

But this just gives you an idea of how we have a risk register that can track the risks that we have, and then also some information on that risk, and then do an evaluation on it to see which one — essentially this weighted one is going to be what we probably are going to want to tackle first and fix first.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →