Security exists to manage risk — the chance a threat exploits a vulnerability and causes harm. Governance ensures it's done consistently.
The Risk Management Lifecycle
How governance, risk and compliance turns uncertainty into decisions.
Tap or hover a part to learn more.
Find the risks.
Catalogue assets, threats and vulnerabilities. You cannot manage a risk you have not identified — asset inventories and threat modelling feed this step.
Check your understanding
1. Which risk treatment moves the risk to a third party?
2. What do you calculate when assessing a risk?
The essentials
- Risk = likelihood × impact. You assess it, then choose a treatment: mitigate (add controls), transfer (insurance), accept (document it) or avoid (stop the activity).
- Governance sets the direction: policies, standards, roles and accountability so security aligns with the business.
- Frameworks give structure — NIST Cyber Security Framework (Identify, Protect, Detect, Respond, Recover) and ISO 27001 (an information security management system).
This is the daily work of a GRC Analyst and connects directly to Security+ governance topics.
