What to do at this stage
- 01
Bring together changes in context, incidents, assurance findings and treatment progress.
- 02
Identify which assessments, controls or risk acceptances need reconsideration.
- 03
Record decisions and follow through on agreed improvements.
Questions to work through
- What has changed since the last decision?
- Are the controls still appropriate for the current threats?
- Which risk acceptances need to be renewed or revised?
A significant incident at a comparable facility may justify examining an assumption before the next scheduled annual review.
A common trap
A calendar review should not delay action when an event has already changed the risk picture.
When the work needs to return
Suggested resources
Selected for their likely use at this stage. Resource associations are guidance, not a compliance crosswalk.
SRMBOK Template 13.2 Risk Register
Record risks, categories, treatment options, risk levels and monitoring comments in an editable Word register.
View in the SRMBOK shopFive Cybersecurity Strategies for Boards and Executives
A short guide for boards and executives on cyber risk priorities and organisational resilience.
View in the SRMBOK shopSRMBOK Guide to Management Systems
Guidance on designing, implementing and maintaining a security risk management system.
View in the SRMBOK shopSRMBOK Guide to Red Teaming and Scenario Modelling
Understand scenario modelling and futures analysis as inputs to security risk assessments and changing-threat reviews.
View in the SRMBOK shopSRMBOK Guide to Governance
Guidance on integrating security risk management into governance, accountability and organisational decision-making.
View in the SRMBOK shopSRMBOK Security Postures Template
Adapt worked examples of security postures that change operational precautions as threat levels change.
View in the SRMBOK shopSRMBOK Risk Assessment Spreadsheet
An enterprise risk workbook linking risk ratings, barriers, treatment actions, review dates and board reporting.
View in the SRMBOK shopKeep the whole life cycle in view
Security Risk Management Life Cycle Wall Charts
Keep the whole life cycle in view, from initiation to change and disposal.
View in the SRMBOK shopGuide to the Security Risk Management Life Cycle
Explore the published SRMBOK guide behind the life cycle.
View in the SRMBOK shopThese practical prompts are editorial guidance for the navigator. Consult the published SRMBOK life cycle guide and charts for the full method. About this edition and its sources.