Risk Register
A Risk Register is the central record of identified risks, their analysis, ownership, and response status. CRISC uses it to track and report risk throughout the risk management lifecycle.
A Risk Register is the central record of identified risks, their analysis, ownership, and response status. CRISC uses it to track and report risk throughout the risk management lifecycle.
IT Risk is the business risk associated with the use, ownership, operation, and adoption of IT within an enterprise.
Risk Appetite is the amount of risk an organization is willing to accept in pursuit of its objectives.
Risk Tolerance is the acceptable variation around the risk appetite for a specific objective or activity.
Inherent Risk is the level of risk before any controls or mitigations are applied.
Residual Risk is the risk that remains after controls and other responses have been applied.
A Risk Register is the central record of identified risks, their analysis, ownership, and response status.
Risk Assessment is the process of identifying, analyzing, and evaluating risk using qualitative or quantitative methods.
Risk Response is the selection and implementation of a treatment — accept, mitigate, transfer, or avoid — for an identified risk.
A Control is a policy, procedure, or safeguard that modifies risk, classified as preventive, detective, or corrective.
A Key Risk Indicator (KRI) is a metric that provides an early warning of rising risk exposure.
A Key Performance Indicator (KPI) measures how well an activity or control is achieving its objectives.
The Three Lines of Defense is a governance model separating risk ownership (operations), risk oversight (risk and compliance functions), and independent assurance (audit).
Risk Governance is the framework of structures, policies, and processes that directs and oversees enterprise risk management.
Business Impact Analysis (BIA) determines the effect of disruptions on business processes to prioritize risk and recovery.
Third-Party Risk is the risk introduced by vendors, suppliers, and other external parties.