Documentation
Structured documentation regarding risk management policies, standards, registers, and other relevant documents is of utmost importance for the effective management of risk. The need and process for documentation should be defined in the risk management policy, strategy, and program. Generally, the following aspects of risk management processes should be documented:
- Risk register: A risk register should include details such as the following:
- Source and nature of risk
- Risk owner
- Risk ranking and severity
- Risk score
- Details about existing controls and additional recommendations
- Asset inventory: An asset inventory should include details such as the following:
- Description of assets
- Asset owner
- Asset classification
- Risk mitigation and action plan: This should include details such as the following:
- Mitigation plan
- Responsibility for mitigation
- Timelines for mitigation
- Results of risk monitoring: These should include the following:
- Monitoring process
- Results...