Document tracking identified risks, their assessment, treatment decisions, and current status.
A risk register is a living document recording identified risks, their assessment (likelihood, impact, risk rating), treatment decisions (mitigate, accept, transfer, avoid), assigned owners, and current status. Risk registers provide visibility into organisational risk exposure and track risk treatment progress. They're essential for ISO 27001 and good practice for any organisation. Regular review ensures the register remains current and risks don't languish without attention.
Why It Matters
The DSC Perspective:
Risk registers turn risk assessment into actionable management. They ensure risks have owners, treatment plans, and ongoing attention. Without a register, identified risks may be forgotten or neglected.
