Documentation
Structured documentation regarding risk management policies, standards, registers, and other relevant processes is of utmost importance for the effective management of risk. The need and process for documentation should be defined in the risk management policy, strategy, and program. Generally, the following aspects of risk management processes should be documented:
- Risk register: A risk register should include details such as the following:
- The source and nature of known risks
- Risk owners
- Risk ranking and severity
- Risk score
- Details about existing controls and additional recommendations
- Asset inventory: An asset inventory should include details such as the following:
- A description of assets
- Asset owners
- Asset classifications
- Risk mitigation and action plan: It should include details such as the following:
- The mitigation plan
- The responsibility for mitigation
- The timelines for mitigation
- Results of risk monitoring: This should include the following:
- The monitoring...