GlossaryGlossary

Risk register

A risk register is a maintained record of security and business risks, their owners, treatment decisions, status, and review history.

August 31, 2026Updated August 2026
Risk managementSecurity governanceFramework readiness

A risk register is a structured list of risks that could affect an organization and the decisions made to manage them.

A practical security risk register normally records:

  • Risk description and affected asset or process
  • Threat, vulnerability, and potential impact
  • Likelihood or risk rating
  • Existing controls
  • Treatment decision, such as reduce, transfer, accept, or avoid
  • Risk owner and action owner
  • Target date, status, and review history

The register should support decisions, not become an archive of vague concerns. It should connect to the controls, policies, evidence, and improvement tasks that address each material risk.

See how to link security risks to controls, policies, and evidence.