What to do at this stage
- 01
Build a short list of plausible security scenarios for each main option.
- 02
Compare the indicative risks, existing protections and important uncertainties.
- 03
Record the assumptions that will need testing in the detailed assessment.
Questions to work through
- Which options change the risk most?
- What remains uncertain at this point?
- Could a different concept avoid a costly treatment later?
Compare two potential sites before signing a lease. Access arrangements, neighbouring activities and emergency response may affect the security concept.
A common trap
A preliminary rating is an aid to choosing a direction; it should not silently become the final accepted risk rating.
Suggested resources
Selected for their likely use at this stage. Resource associations are guidance, not a compliance crosswalk.
ISO 31000 Risk Management Process — One-Page Guide
Keep the risk management process in view while structuring your assessment.
View in the SRMBOK shopRisk Register Starter Pack
Start documenting risks and the actions needed to treat them.
View in the SRMBOK shopRisk Thinking for Domestic and Family Violence Practice (an SRMBOK Guide)
Risk thinking for domestic and family violence practitioners, covering uncertainty, controls and defensible decisions. A companion to mandated assessment processes.
View in the SRMBOK shopThe Risk Bow-Tie Method eBook
Learn the bow-tie method through its nine elements, a factory-fire example and a workshop outline.
View in the SRMBOK shopSRMBOK Template 13.2 Risk Register
Record risks, categories, treatment options, risk levels and monitoring comments in an editable Word register.
View in the SRMBOK shopRisk Assessment Template
Give a security risk assessment report a consistent structure.
View in the SRMBOK shopSRMBOK Guide to Red Teaming and Scenario Modelling
Understand scenario modelling and futures analysis as inputs to security risk assessments and changing-threat reviews.
View in the SRMBOK shopSRMBOK Guide to the Risk Management Process
A printable explanation of the risk management process, distinguishing assessment actions from the supporting activities.
View in the SRMBOK shopControl Effectiveness Assessment - PDF A4 Organisational Licence
Learn a control-effectiveness method using design, capability, feedback and evidence, with worked cases and calibration exercises.
View in the SRMBOK shopSRMBOK ISO27000 Cybersecurity Review Tool
An editable Excel review tool combining a cyber control checklist, scorecard and control-effectiveness assessment.
View in the SRMBOK shopSRMBOK Risk Assessment Spreadsheet
An enterprise risk workbook linking risk ratings, barriers, treatment actions, review dates and board reporting.
View in the SRMBOK shopEnterprise Security Risk Assessment Template
Adapt a fully worked enterprise security risk assessment using a fictional corporation, with editable examples and treatment content.
View in the SRMBOK shopKeep the whole life cycle in view
Security Risk Management Life Cycle Wall Charts
Keep the whole life cycle in view, from initiation to change and disposal.
View in the SRMBOK shopGuide to the Security Risk Management Life Cycle
Explore the published SRMBOK guide behind the life cycle.
View in the SRMBOK shopThese practical prompts are editorial guidance for the navigator. Consult the published SRMBOK life cycle guide and charts for the full method. About this edition and its sources.