Risk criteria
Define impact, likelihood, scoring, risk acceptance, escalation, and treatment expectations.
Exact scope, evidence, access, stakeholders, and acceptance criteria are agreed before delivery.
Define impact, likelihood, scoring, risk acceptance, escalation, and treatment expectations.
Identify critical processes, information, systems, suppliers, owners, dependencies, and existing controls.
Document credible threats, vulnerabilities, control conditions, impacts, likelihood, and residual risk.
Prioritize risk treatment, owners, target dates, dependencies, acceptance decisions, and reporting.
Confirm the business driver, environment, stakeholders, boundaries, assumptions, and evidence needs.
Review the current state, evidence, architecture, risks, dependencies, and material gaps.
Develop the agreed controls, artifacts, recommendations, implementation, or operating routines.
Confirm completion, residual risk, ownership, reporting, and the next improvement priorities.