Importance of a risk register
All risks identified in the risk assessment should be entered into a risk register, which could be a sophisticated Software-as-a-Service (SaaS) program or a spreadsheet. At a minimum, the risk register is to maintain details of threats, vulnerabilities, likelihood, impact, inherent risk, current controls, residual risk, countermeasures that will reduce the risk in the future, and a risk owner.
Not all the risks captured in the risk register will have the same priority, and a risk practitioner should dedicate sufficient time to determine which risks should be prioritized for remediation and which should be revisited later.
The best way to identify the risks that should be prioritized is to discuss the likelihood and impact with the stakeholders at the time of risk assessment. This helps the risk manager to eliminate guesswork on which risks could cause more damage to the organization and should be remediated on priority. If a risk cannot be remediated...