Skip to content

Security Risk Management

What is Security Risk Management?

The ongoing process of identifying, analyzing, evaluating, and treating risks to an organization's information security.

Risk Management

Each of these is named in at least one of the same controls as security risk management. The number is how many controls name both.

What the standards actually require on security risk management

Requirements naming security risk management across 6 standards, quoted from the control text.

ISO 27005:20223 controls

Requirement defined in ISO 27005:2022, clause 5.2 (Information security risk management cycles). See licensed source for normative text.

iso-27005-2022::5.2 · Information security risk management cycles

Apply security risk management per NZISM Chapter 20 + ISO 31000 + NZ ISO/AS 31000:2018 covering risk identification + assessment + treatment + monitoring + governance reporting.

NZISM-8 · Security Risk Management, Vulnerability Management, and Incident Reporting

ITSG-33 Annex 2: the Information System Security Implementation Process (ISSIP) - integrating security into the system development life cycle of each information system.

ITSG33-RMP-2 · Information System Security Risk Management Activities / ISSIP (Annex 2)

Establish and maintain a cyber security risk management strategy and program covering both IT and operational technology (OT).

AESCSF-RM-1 · Establish cyber security risk management strategy

The CISO coordinates security risk management activities between cyber security and business teams.

ISM-0726 · The CISO coordinates security risk management activities between cyber security and busine

Institution maintains a documented risk management framework integrating information security risk into enterprise risk management.

IS-III.A.1 · Information Security Risk Management Framework

Questions people ask about security risk management

What is Security Risk Management?
The ongoing process of identifying, analyzing, evaluating, and treating risks to an organization's information security.
Why is Security Risk Management important for compliance?
Security Risk Management is a key concept in Risk Management. Understanding security risk management helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Security Risk Management?
Security Risk Management appears in the requirement text of ISO 27005:2022, New Zealand Information Security Manual (NZISM), Canada ITSG-33 - IT Security Risk Management, Australian Energy Sector Cyber Security Framework (AESCSF), Australian Information Security Manual. Across these standards we have identified 11 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Security Risk Management?
Explore our compliance framework pages to see how security risk management applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Security Risk Management applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.