A risk register is a structured list of risks that could affect an organization and the decisions made to manage them.
A practical security risk register normally records:
- Risk description and affected asset or process
- Threat, vulnerability, and potential impact
- Likelihood or risk rating
- Existing controls
- Treatment decision, such as reduce, transfer, accept, or avoid
- Risk owner and action owner
- Target date, status, and review history
The register should support decisions, not become an archive of vague concerns. It should connect to the controls, policies, evidence, and improvement tasks that address each material risk.
See how to link security risks to controls, policies, and evidence.
