Test Your Knowledge
Key Takeaways
- A risk register is the central artifact of any risk management program — required by ISO 27001, NIST, and SOC 2
- Every entry needs: risk ID, description, likelihood, impact, inherent score, controls, residual score, owner, and treatment plan
- Use a 5x5 matrix to consistently score likelihood (1-5) and impact (1-5) for a maximum score of 25
- Four treatment options: mitigate (reduce), transfer (insure/outsource), accept (acknowledge), or avoid (eliminate)
- Review quarterly at minimum — critical and high risks monthly
Building an Effective Risk Register
A risk register is the foundational document of any cybersecurity risk management program. It provides a structured, auditable record of identified risks, how they have been assessed, what controls are in place, and what actions are planned. Whether you are preparing for ISO 27001 certification, a SOC 2 audit, or simply building a mature security program, a well-maintained risk register is essential. This guide covers the components, scoring methodology, sample entries, and framework alignment you need to build one from scratch.
Risk Register Components
| Field | Description | Example |
|---|---|---|
| Risk ID | Unique identifier | RISK-2026-001 |
| Category | Risk domain (Operational, Technical, Compliance, Strategic) | Technical |
| Description | Clear statement of the risk scenario | Unpatched critical vulnerability in internet-facing web server |
| Likelihood | Probability of occurrence (1-5) | 4 (Likely) |
| Impact | Business impact if realized (1-5) | 5 (Critical) |
| Inherent Risk | Likelihood x Impact (before controls) | 20 (Critical) |
| Current Controls | Existing mitigations in place | WAF, monthly patching cycle, IDS monitoring |
| Residual Risk | Risk score after controls are applied | 10 (Medium) |
| Risk Owner | Person accountable for managing this risk | CISO |
| Treatment | Mitigate, Transfer, Accept, or Avoid | Mitigate |
| Action Plan | Specific steps to reduce residual risk | Implement automated patching within 48h for critical CVEs |
| Target Date | Deadline for action plan completion | 2026-04-30 |
| Status | Open, In Progress, Closed, Accepted | In Progress |
5x5 Risk Matrix
The risk matrix maps likelihood against impact to produce a risk score from 1 to 25. Color coding provides immediate visual prioritization.
| Likelihood / Impact | 1 - Negligible | 2 - Minor | 3 - Moderate | 4 - Major | 5 - Critical |
|---|---|---|---|---|---|
| 5 - Almost Certain | 5 | 10 | 15 | 20 | 25 |
| 4 - Likely | 4 | 8 | 12 | 16 | 20 |
| 3 - Possible | 3 | 6 | 9 | 12 | 15 |
| 2 - Unlikely | 2 | 4 | 6 | 8 | 10 |
| 1 - Rare | 1 | 2 | 3 | 4 | 5 |
Risk Bands: Low (1-6) Medium (7-10) High (11-15) Critical (16-25)
Sample Risk Register Entries
| ID | Risk | L | I | Score | Controls | Treatment |
|---|---|---|---|---|---|---|
| R-001 | Ransomware encrypts critical business systems | 3 | 5 | 15 | EDR, offline backups, network segmentation | Mitigate + Transfer (cyber insurance) |
| R-002 | Phishing leads to credential compromise | 4 | 4 | 16 | MFA, security awareness training, email filtering | Mitigate |
| R-003 | Third-party vendor data breach | 3 | 4 | 12 | Vendor risk assessments, contractual controls, data minimization | Mitigate + Transfer |
| R-004 | Insider threat — data exfiltration by employee | 2 | 5 | 10 | DLP, UEBA, access reviews, background checks | Mitigate |
| R-005 | Regulatory non-compliance (GDPR/CCPA) | 2 | 4 | 8 | Privacy program, DPIA process, consent management | Mitigate |
Framework Alignment
Your risk register methodology should align with established risk management frameworks. Here is how the risk register maps to common standards.
| Framework | Risk Register Requirement | Key Guidance |
|---|---|---|
| ISO 27005 | Risk assessment and treatment — risk register is the primary output | Defines risk identification, analysis, evaluation, and treatment process |
| NIST SP 800-30 | Risk assessment process — documenting threats, vulnerabilities, likelihood, impact | Provides qualitative and semi-quantitative scoring methodologies |
| NIST CSF 2.0 | GOVERN and IDENTIFY functions require documented risk assessment | Risk register supports GV.RM and ID.RA subcategories |
| SOC 2 | CC3.2 — Entity identifies and assesses risks | Auditors expect a maintained risk register with evidence of periodic review |
| ISO 27001 | Clause 6.1.2 — Information security risk assessment | Risk register must be maintained and reviewed as part of the ISMS |
| COBIT | APO12 — Manage Risk | Risk register feeds into IT risk profile and is input to risk responses |
Risk Treatment Options
| Option | Action | When to Use | Example |
|---|---|---|---|
| Mitigate | Implement controls to reduce likelihood or impact | Risk is above tolerance and can be reduced cost-effectively | Deploy MFA to reduce credential compromise risk |
| Transfer | Shift risk to a third party (insurance, outsourcing) | Financial impact is high but probability is low; risk can be contractually shared | Purchase cyber insurance for ransomware scenario |
| Accept | Acknowledge and document the risk without further action | Risk is within tolerance, or cost of mitigation exceeds potential loss | Accept low-severity vulnerability on internal-only system |
| Avoid | Eliminate the risk by removing the activity or asset | Risk is too high and no effective mitigation exists | Discontinue a legacy application with unfixable vulnerabilities |
Explore More Compliance Guides
For comprehensive tutorials and security guides:
Visit FixTheVuln.com →Related Resources
FixTheVuln Store
Study Planners Available for Both Certs
Fillable PDF study planners with domain trackers, weekly schedules, and progress tracking. Available in Standard, ADHD-Friendly, Dark Mode, and 4-Format Bundle.
ISACA CRISC Planner ISC2 CISSP Planner60+ certifications available — from $5.99
CyberFolio
Choosing your next cert? Track them all in one place.
Build a shareable cybersecurity portfolio that highlights your certifications, projects, and skills — free.
Build Your Portfolio →