Risk Identification
Risk management begins with risk identification. Risk identification is the process of identifying and listing risks in the risk register.
The primary objective of the risk identification process is to recognize threats, vulnerabilities, assets, and controls of the organization. A risk practitioner can use the following sources for the identification of any risk:
- Review of past audit reports
- Review of incident reports
- Review of public media articles and press releases
- Systematic approaches such as vulnerability assessments, penetration testing, review of business continuity plan (BCP) and disaster recovery plan (DRP) documents, interviews with senior management and process owners, and scenario analysis
All the identified risks should be captured in the risk register along with details such as description, category, probability, impact, and risk owner. In fact, maintenance of the risk register process starts with the risk identification...