Glossary

Risk Register

A risk register is the structured, living record of your identified risks: what could go wrong, how likely, how bad, who owns it, and what you’re doing about it. Every serious framework — SOC 2, ISO 27001, HIPAA’s risk analysis, MAS TRM — expects one, and auditors sample it directly.

The anatomy of a useful entry

Description in concrete terms (“laptop with production access stolen,” not “endpoint risk”); likelihood and impact scores from your stated methodology; the resulting risk level; the treatment decision — mitigate, accept, transfer, avoid — with rationale; an owner by name; linked controls; and a review date. The decision and the owner are what separate a register from a spreadsheet of worries.

What auditors check

That the register exists and is current; that scoring follows your documented methodology; that high risks have treatments with real progress; and that acceptance decisions were made by someone with authority to accept them. A register last touched eleven months ago fails the “living” test on its timestamps alone.

The practical cadence

Review quarterly, update on trigger events (new vendor, new product surface, incident, architecture change), and feed the top risks into leadership meetings — minutes referencing the register are governance evidence auditors and regulators both love.

Related Terms

Continuous Monitoring — Continuous monitoring is the automated, ongoing testing of security controls — replacing point-in-time evidence scrambles with always-current audit readiness.

Gap Assessment — A gap assessment maps your current controls against a framework's requirements and produces the remediation plan that makes audit readiness plannable.

ISMS — An ISMS is the management system ISO 27001 certifies — the loop of risk assessment, controls, internal audit, and review that runs your security program.