Security Risk Management
What is Security Risk Management?
The ongoing process of identifying, analyzing, evaluating, and treating risks to an organization's information security.
Terms that appear alongside security risk management
Each of these is named in at least one of the same controls as security risk management. The number is how many controls name both.
- information security 8 shared controls
- governance 5 shared controls
- risk management framework 5 shared controls
- risk management plan 3 shared controls
- iso 27005 3 shared controls
- information system 2 shared controls
- incident response 2 shared controls
- incident reporting 2 shared controls
Frameworks that govern security risk management
What the standards actually require on security risk management
Requirements naming security risk management across 6 standards, quoted from the control text.
Requirement defined in ISO 27005:2022, clause 5.2 (Information security risk management cycles). See licensed source for normative text.
iso-27005-2022::5.2 · Information security risk management cycles →Apply security risk management per NZISM Chapter 20 + ISO 31000 + NZ ISO/AS 31000:2018 covering risk identification + assessment + treatment + monitoring + governance reporting.
NZISM-8 · Security Risk Management, Vulnerability Management, and Incident Reporting →ITSG-33 Annex 2: the Information System Security Implementation Process (ISSIP) - integrating security into the system development life cycle of each information system.
ITSG33-RMP-2 · Information System Security Risk Management Activities / ISSIP (Annex 2) →Establish and maintain a cyber security risk management strategy and program covering both IT and operational technology (OT).
AESCSF-RM-1 · Establish cyber security risk management strategy →The CISO coordinates security risk management activities between cyber security and business teams.
ISM-0726 · The CISO coordinates security risk management activities between cyber security and busine →Institution maintains a documented risk management framework integrating information security risk into enterprise risk management.
IS-III.A.1 · Information Security Risk Management Framework →Questions people ask about security risk management
What is Security Risk Management?
Why is Security Risk Management important for compliance?
Which compliance frameworks address Security Risk Management?
Where can I learn more about Security Risk Management?
See how Security Risk Management applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.