What to do at this stage
- 01
Identify the people, assets, information and services within scope, including important dependencies.
- 02
Describe plausible threats and the consequences of losing a critical capability.
- 03
Agree risk criteria and document the assumptions and evidence that shape the assessment.
Questions to work through
- What would be most difficult to lose or replace?
- Which threats are relevant to this setting?
- Are existing controls being credited on evidence?
A laboratory may depend on a small refrigeration system more than on a much more expensive but replaceable item of equipment. Criticality helps distinguish those priorities.
A common trap
Asset purchase price alone is an incomplete measure of the consequence of its loss.
When the work needs to return
Suggested resources
Selected for their likely use at this stage. Resource associations are guidance, not a compliance crosswalk.
Worked Example: Information and System Value Assessment
See an example of how information and system value can be assessed.
View in the SRMBOK shopSRMBOK Guide to ChatGPT Prompt Engineering
Use and adapt prompts for risk identification, assessment, stakeholder engagement and treatment planning.
View in the SRMBOK shopRisk Thinking for Domestic and Family Violence Practice (an SRMBOK Guide)
Risk thinking for domestic and family violence practitioners, covering uncertainty, controls and defensible decisions. A companion to mandated assessment processes.
View in the SRMBOK shopSecurity Risk Assessment Process Flow Template
An editable Excel process flow for documenting the security risk assessment procedure.
View in the SRMBOK shopInformation and System Value Assessment (ISVA)
Support the assessment of information and system criticality.
View in the SRMBOK shopSRMBOK Template 13.7 Property Selection and Security Planning Checklist
An editable property selection checklist covering the site, building, access, security systems and emergency provisions.
View in the SRMBOK shopSRMBOK Guide to AI for Risk Practitioners (Ed. 1.0).pdf
Practical guidance on AI use, information handling, verification and the evidence behind professional risk judgements.
View in the SRMBOK shopSRMBOK Guide to Managing Explosives Threats
Understand explosives threats and an integrated approach to assessing, mitigating and managing related incidents.
View in the SRMBOK shopSRMBOK Guide to the Risk Management Process
A printable explanation of the risk management process, distinguishing assessment actions from the supporting activities.
View in the SRMBOK shopSRMBOK Guide to Intellectual Assets
Guidance on protecting intellectual assets, with attention to research environments, organisational culture and information risks.
View in the SRMBOK shopSRMBOK Guide to the 30 Day Risk Assessment
A structured assessment method with workshop materials, facilitator guidance, checklists and planning templates.
View in the SRMBOK shopSRMBOK Guide to Insider Threat Management Programs
Guidance on establishing an insider threat programme, from assessment and policies to awareness, detection and response.
View in the SRMBOK shopEnterprise Security Risk Assessment Template
Adapt a fully worked enterprise security risk assessment using a fictional corporation, with editable examples and treatment content.
View in the SRMBOK shopKeep the whole life cycle in view
Security Risk Management Life Cycle Wall Charts
Keep the whole life cycle in view, from initiation to change and disposal.
View in the SRMBOK shopGuide to the Security Risk Management Life Cycle
Explore the published SRMBOK guide behind the life cycle.
View in the SRMBOK shopThese practical prompts are editorial guidance for the navigator. Consult the published SRMBOK life cycle guide and charts for the full method. About this edition and its sources.