Risk Management Workflows
- Process Exit Criteria
- Risk process continues until the process response is implemented
- Risk is mitigated to acceptable managed residual risk or removed
- Mitigated risk where significance is less than “9” & appropriate controls are identified for ongoing risk management
- Measurements
- Number of risk management meetings
- Number of improvement projects
- Number of improvements to the risk assessment process
- Level of funding allocated to risk management projects
- Number & frequency of updates to published Governance Committee reports
- Risk limits & policies
- To Sum it Up – Just Do It
- Risks management policy signed by CISO, CFO and CIO
- ERM & Security manager responsibilities assigned
- Appropriate funding allocated (if required)
- Risk awareness training
- Meeting time and standard agenda format established
- Support sessions to enter risk items
- Risk meeting agenda posted
- Risk meetings and Quarterly Governance Meetings
- Posted risk meeting action items and notes
- Follow up risk response
Iterate enter risks - update risks - post agenda – meeting - post notes - follow up risk response

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics