What to do at this stage
- 01
Describe each scenario clearly enough to identify its causes, event and consequences.
- 02
Evaluate the controls that actually operate and record the basis for crediting them.
- 03
Document the current risk, uncertainty and findings for the risk owner to consider.
Questions to work through
- What could happen, and through which pathway?
- Which controls are operating effectively?
- What evidence would change this assessment?
For unauthorised access to a critical room, examine permissions, door behaviour, monitoring and response. A written access policy alone does not establish that these controls work.
A common trap
Treating planned controls as already effective can understate the current risk.
When the work needs to return
Suggested resources
Selected for their likely use at this stage. Resource associations are guidance, not a compliance crosswalk.
ISO 31000 Risk Management Process — One-Page Guide
Keep the risk management process in view while structuring your assessment.
View in the SRMBOK shopThe Bow-Tie Field Kit
Support a bow-tie workshop and review the resulting analysis.
View in the SRMBOK shopRisk Register — Template 13.1
Organise assessment findings in a consistent risk register.
View in the SRMBOK shopSRMBOK Guide to ChatGPT Prompt Engineering
Use and adapt prompts for risk identification, assessment, stakeholder engagement and treatment planning.
View in the SRMBOK shopRisk Thinking for Domestic and Family Violence Practice (an SRMBOK Guide)
Risk thinking for domestic and family violence practitioners, covering uncertainty, controls and defensible decisions. A companion to mandated assessment processes.
View in the SRMBOK shopThe Risk Bow-Tie Method eBook
Learn the bow-tie method through its nine elements, a factory-fire example and a workshop outline.
View in the SRMBOK shopSecurity Risk Assessment Process Flow Template
An editable Excel process flow for documenting the security risk assessment procedure.
View in the SRMBOK shopSRMBOK Template 13.2 Risk Register
Record risks, categories, treatment options, risk levels and monitoring comments in an editable Word register.
View in the SRMBOK shopRisk Assessment Template
Give a security risk assessment report a consistent structure.
View in the SRMBOK shopSRMBOK Guide to Red Teaming and Scenario Modelling
Understand scenario modelling and futures analysis as inputs to security risk assessments and changing-threat reviews.
View in the SRMBOK shopSRMBOK Guide to AI for Risk Practitioners (Ed. 1.0).pdf
Practical guidance on AI use, information handling, verification and the evidence behind professional risk judgements.
View in the SRMBOK shopSRMBOK Guide to Managing Explosives Threats
Understand explosives threats and an integrated approach to assessing, mitigating and managing related incidents.
View in the SRMBOK shopSRMBOK Guide to the Risk Management Process
A printable explanation of the risk management process, distinguishing assessment actions from the supporting activities.
View in the SRMBOK shopSRMBOK Guide to Intellectual Assets
Guidance on protecting intellectual assets, with attention to research environments, organisational culture and information risks.
View in the SRMBOK shopSRMBOK Guide to the 30 Day Risk Assessment
A structured assessment method with workshop materials, facilitator guidance, checklists and planning templates.
View in the SRMBOK shopSRMBOK Guide to Insider Threat Management Programs
Guidance on establishing an insider threat programme, from assessment and policies to awareness, detection and response.
View in the SRMBOK shopSRMBOK Risk Assessment Spreadsheet
An enterprise risk workbook linking risk ratings, barriers, treatment actions, review dates and board reporting.
View in the SRMBOK shopEnterprise Security Risk Assessment Template
Adapt a fully worked enterprise security risk assessment using a fictional corporation, with editable examples and treatment content.
View in the SRMBOK shopKeep the whole life cycle in view
Security Risk Management Life Cycle Wall Charts
Keep the whole life cycle in view, from initiation to change and disposal.
View in the SRMBOK shopGuide to the Security Risk Management Life Cycle
Explore the published SRMBOK guide behind the life cycle.
View in the SRMBOK shopThese practical prompts are editorial guidance for the navigator. Consult the published SRMBOK life cycle guide and charts for the full method. About this edition and its sources.