Lab 01 — Build an Enterprise Risk Register
Mission Information
Section titled “Mission Information”| Item | Details |
|---|---|
| Lab | Lab 01 — Build an Enterprise Risk Register |
| Module | 01 — GRC Fundamentals |
| Difficulty | Beginner → Intermediate |
| Estimated Time | 90–120 Minutes |
| Role | GRC Analyst / Cybersecurity Risk Analyst |
| Primary Deliverable | Enterprise Cybersecurity Risk Register |
| Environment | Spreadsheet / GRC Workspace |
| Lab Type | Governance, Risk & Compliance |
Mission Scenario
Section titled “Mission Scenario”You have recently joined NorthStar Digital Services, a fictional enterprise providing cloud-based services to business customers.
The organization has grown rapidly.
Over the last several years, new:
-
Cloud platforms.
-
SaaS applications.
-
Remote-working technologies.
-
Vendors.
-
Business applications.
-
Customer-facing services.
have been introduced.
However, cybersecurity risks are currently tracked inconsistently.
Some teams maintain spreadsheets.
Others track security issues through tickets.
Several risks are discussed during meetings but are never formally documented.
Leadership has therefore asked the GRC team to establish a centralized:
Enterprise Cybersecurity Risk Register
Your responsibility is to build the first version of this register.
You must identify meaningful risk scenarios, assess their severity, identify existing controls, determine residual risk, assign ownership, recommend treatment strategies, and create a summary suitable for senior management.
Mission Objectives
Section titled “Mission Objectives”By completing this lab, you will learn how to:
-
Build an enterprise risk register.
-
Identify cybersecurity risk scenarios.
-
Write clear risk statements.
-
Identify threats and vulnerabilities.
-
Identify affected assets.
-
Determine business impact.
-
Assign risk owners.
-
Define likelihood and impact scales.
-
Calculate inherent risk.
-
Identify existing controls.
-
Evaluate control effectiveness.
-
Calculate residual risk.
-
Select risk-treatment strategies.
-
Develop remediation plans.
-
Establish target dates.
-
Track risk status.
-
Identify risks requiring escalation.
-
Build executive risk reporting.
Prerequisites
Section titled “Prerequisites”Before beginning this lab, you should understand:
-
Security governance.
-
Enterprise Risk Management.
-
Risk assessment methodology.
-
Likelihood and impact.
-
Inherent risk.
-
Residual risk.
-
Risk treatment.
-
Security controls.
-
Control effectiveness.
Recommended lessons:
02 Security Governance
03 Enterprise Risk Management
04 Risk Assessment Methodology
07 Control Design & Implementation
08 Control Testing & EffectivenessLab Architecture
Section titled “Lab Architecture”You will build the following workflow:
Business Environment ↓Assets & Processes ↓Threats ↓Vulnerabilities ↓Risk Scenarios ↓Likelihood × Impact ↓Inherent Risk ↓Existing Controls ↓Control Effectiveness ↓Residual Risk ↓Risk Treatment ↓Remediation Plan ↓Risk Owner ↓Monitoring & ReportingPart 1 — Understand the Organization
Section titled “Part 1 — Understand the Organization”Before assessing risk, understand the business.
NorthStar Digital Services operates the following environment.
Business Services
Section titled “Business Services”The organization provides:
-
Customer SaaS applications.
-
Online customer portals.
-
Managed cloud services.
-
Technical consulting.
-
Customer support.
Approximately:
Employees: 2,500
Customers: 1,200+
Primary Cloud Platform: AWS
Secondary Cloud Platform: Azure
Corporate Identity: Microsoft Entra ID
Endpoint Fleet: Windows and macOS
Remote Workforce: 65%The organization processes:
-
Customer information.
-
Employee information.
-
Financial information.
-
Authentication information.
-
Application logs.
-
Business-confidential information.
Part 2 — Identify Critical Assets
Section titled “Part 2 — Identify Critical Assets”Your first task is to identify important assets.
Create an Asset Inventory worksheet.
Use the following columns:
| Asset ID | Asset | Type | Business Owner | Criticality |
|---|
Start with:
| Asset ID | Asset | Type | Business Owner | Criticality |
|---|---|---|---|---|
| AST-001 | Customer SaaS Platform | Application | Product | Critical |
| AST-002 | AWS Production Environment | Cloud | Cloud Engineering | Critical |
| AST-003 | Microsoft Entra ID | Identity | IT | Critical |
| AST-004 | Customer Database | Data | Product | Critical |
| AST-005 | Employee Endpoints | Endpoint | IT | High |
| AST-006 | Corporate Email | SaaS | IT | High |
| AST-007 | Source Code Repositories | Development | Engineering | High |
| AST-008 | Backup Platform | Infrastructure | IT | Critical |
Student Action
Section titled “Student Action”Add at least five additional assets that you believe should be included.
Consider:
-
Network infrastructure.
-
CI/CD platforms.
-
HR systems.
-
Finance systems.
-
Security platforms.
-
Vendor services.
-
Customer-support systems.
Why This Matters
Section titled “Why This Matters”Risk cannot be properly evaluated without understanding what the organization is trying to protect.
Part 3 — Define the Risk Methodology
Section titled “Part 3 — Define the Risk Methodology”Before assigning scores, define consistent criteria.
You will use a 5 × 5 risk matrix.
Risk score:
Risk Score = Likelihood × ImpactPart 4 — Define Likelihood
Section titled “Part 4 — Define Likelihood”Create the following scale.
| Score | Rating | Description |
|---|---|---|
| 1 | Rare | Highly unlikely |
| 2 | Unlikely | Could occur but not expected |
| 3 | Possible | Could reasonably occur |
| 4 | Likely | Expected to occur |
| 5 | Almost Certain | Expected frequently |
Part 5 — Define Impact
Section titled “Part 5 — Define Impact”Use:
| Score | Rating | Description |
|---|---|---|
| 1 | Insignificant | Minimal business impact |
| 2 | Minor | Limited disruption |
| 3 | Moderate | Material operational or financial impact |
| 4 | Major | Significant business/customer impact |
| 5 | Severe | Enterprise-level or regulatory impact |
When assigning impact, consider:
Confidentiality
Integrity
Availability
Financial Loss
Regulatory Exposure
Customer Impact
Operational Disruption
ReputationPart 6 — Define Risk Ratings
Section titled “Part 6 — Define Risk Ratings”Use:
| Score | Rating |
|---|---|
| 1–4 | Low |
| 5–9 | Moderate |
| 10–16 | High |
| 17–25 | Critical |
Your methodology should be documented before assessing risks.
This prevents teams from changing scoring rules to produce preferred results.
Part 7 — Create the Risk Register
Section titled “Part 7 — Create the Risk Register”Create a worksheet named:
Enterprise Risk RegisterUse these columns:
| Field |
|---|
| Risk ID |
| Risk Title |
| Risk Statement |
| Asset / Process |
| Threat |
| Vulnerability |
| Business Impact |
| Likelihood |
| Impact |
| Inherent Risk Score |
| Inherent Rating |
| Existing Controls |
| Control Effectiveness |
| Residual Likelihood |
| Residual Impact |
| Residual Risk Score |
| Residual Rating |
| Risk Owner |
| Risk Treatment |
| Remediation Action |
| Target Date |
| Status |
Part 8 — Write Risk Statements
Section titled “Part 8 — Write Risk Statements”A useful structure is:
There is a risk that [threat/event] may exploit [condition/vulnerability], resulting in [business impact].
Avoid weak entries such as:
Phishing RiskInstead write:
There is a risk that threat actors may successfully compromise employee credentials through phishing because employees rely on phishing-susceptible authentication methods, resulting in unauthorized access to corporate systems and sensitive information.
The second statement explains:
Threat +Weakness +Event +ImpactPart 9 — Risk Scenario 01: Phishing
Section titled “Part 9 — Risk Scenario 01: Phishing”Create:
Risk ID:RISK-001
Risk Title:Employee Credential Compromise Through PhishingRisk statement:
There is a risk that threat actors may compromise employee credentials through phishing attacks, resulting in unauthorized access to corporate systems, sensitive information, and cloud resources.
Affected assets:
Corporate Email
Microsoft Entra ID
SaaS ApplicationsThreat:
External Threat ActorVulnerability:
Phishing-susceptible authenticationand employee susceptibilityPart 10 — Assess Inherent Risk
Section titled “Part 10 — Assess Inherent Risk”Assume there are no controls.
Assign:
Likelihood = 5
Impact = 4Calculate:
5 × 4 = 20Therefore:
Inherent Risk = 20 — CriticalRecord this in your register.
Part 11 — Identify Existing Controls
Section titled “Part 11 — Identify Existing Controls”NorthStar currently uses:
-
MFA.
-
Email filtering.
-
Security awareness training.
-
Endpoint protection.
-
Conditional Access.
-
Security monitoring.
Record these under:
Existing ControlsPart 12 — Evaluate Control Effectiveness
Section titled “Part 12 — Evaluate Control Effectiveness”Use:
| Rating | Description |
|---|---|
| Effective | Control consistently reduces risk |
| Partially Effective | Some weaknesses exist |
| Ineffective | Control provides little meaningful reduction |
| Not Tested | Effectiveness has not been validated |
For this scenario assume:
Control Effectiveness:Partially EffectiveWhy?
Because standard MFA remains susceptible to some advanced phishing techniques.
Part 13 — Calculate Residual Risk
Section titled “Part 13 — Calculate Residual Risk”After considering controls:
Residual Likelihood = 3
Residual Impact = 4Calculate:
3 × 4 = 12Therefore:
Residual Risk = 12 — HighYour register now demonstrates:
Inherent Risk20 — Critical
↓ Controls
Residual Risk12 — HighPart 14 — Select Risk Treatment
Section titled “Part 14 — Select Risk Treatment”Use four common strategies:
Mitigate
Avoid
Transfer
AcceptFor RISK-001 choose:
Treatment:MitigatePart 15 — Define Remediation
Section titled “Part 15 — Define Remediation”Recommended action:
Implement phishing-resistant authentication for privileged and high-risk users and progressively expand deployment across the workforce.
Possible technology approaches include:
-
FIDO2 security keys.
-
Passkeys.
-
Certificate-based authentication.
Add:
Risk Owner:Chief Information Security Officer
Target:90 Days
Status:OpenPart 16 — Risk Scenario 02: Cloud Misconfiguration
Section titled “Part 16 — Risk Scenario 02: Cloud Misconfiguration”Create:
Risk ID:RISK-002
Risk Title:Exposure of Sensitive Data Through Cloud MisconfigurationRisk statement:
There is a risk that cloud resources may be incorrectly configured, resulting in unauthorized public exposure of customer or business-sensitive information.
Threat:
External Threat ActorVulnerability:
Cloud configuration errorsAffected assets:
AWS Production Environment
Customer Database
Cloud StorageAssign:
Likelihood = 4
Impact = 5Therefore:
Inherent Risk = 20 — CriticalPart 17 — Existing Cloud Controls
Section titled “Part 17 — Existing Cloud Controls”Assume NorthStar uses:
-
Infrastructure as Code.
-
Cloud configuration monitoring.
-
IAM policies.
-
Security groups.
-
Encryption.
-
Cloud logging.
Control effectiveness:
Partially EffectiveResidual assessment:
Likelihood = 3
Impact = 5Therefore:
Residual Risk = 15 — HighTreatment:
MitigateRecommended remediation:
Implement automated policy-as-code validation within CI/CD pipelines to prevent insecure cloud configurations before deployment.
Part 18 — Risk Scenario 03: Ransomware
Section titled “Part 18 — Risk Scenario 03: Ransomware”Create:
RISK-003
Enterprise Ransomware AttackRisk statement:
There is a risk that ransomware may compromise enterprise endpoints and infrastructure, causing system outages, data loss, business disruption, and financial impact.
Consider:
Threat:Cybercriminal Group
Vulnerability:Endpoint compromise or credential theft
Assets:EndpointsServersFile SystemsBackupsAssign your own:
-
Likelihood.
-
Impact.
-
Controls.
-
Residual score.
-
Treatment.
Document your reasoning.
Part 19 — Risk Scenario 04: Privileged Account Compromise
Section titled “Part 19 — Risk Scenario 04: Privileged Account Compromise”Create:
RISK-004
Privileged Account CompromisePotential threats:
Credential Theft
Insider Threat
Session HijackingPossible weaknesses:
Excessive Privilege
Weak MFA
Standing Administrative Access
Poor MonitoringPotential controls:
PAM
MFA
Conditional Access
Privileged Activity Monitoring
Access ReviewsPerform the complete assessment yourself.
Part 20 — Risk Scenario 05: Third-Party SaaS Breach
Section titled “Part 20 — Risk Scenario 05: Third-Party SaaS Breach”Create:
RISK-005
Sensitive Data Exposure Through SaaS Vendor BreachPotential impact:
-
Customer data exposure.
-
Regulatory impact.
-
Customer notification.
-
Contractual impact.
-
Reputation damage.
Possible controls:
-
Vendor security assessment.
-
SOC report review.
-
Contractual security requirements.
-
Encryption.
-
Data minimization.
-
Vendor monitoring.
Complete the scoring.
Part 21 — Risk Scenario 06: Unpatched Critical Vulnerability
Section titled “Part 21 — Risk Scenario 06: Unpatched Critical Vulnerability”Create:
RISK-006
Exploitation of Critical Internet-Facing VulnerabilityPotential weakness:
Delayed patchingPotential threat:
External attackerPossible controls:
Vulnerability Scanning
Patch Management
WAF
EDR
Threat Intelligence
Attack Surface MonitoringAssess inherent and residual risk.
Part 22 — Risk Scenario 07: Cloud Service Outage
Section titled “Part 22 — Risk Scenario 07: Cloud Service Outage”Create:
RISK-007
Business Disruption Due to Cloud Service OutageConsider:
-
Cloud region dependency.
-
Single-region architecture.
-
Recovery capabilities.
-
Backups.
-
Availability requirements.
Possible treatments:
Mitigate
Transfer
AcceptSelect and justify one.
Part 23 — Risk Scenario 08: Insider Data Theft
Section titled “Part 23 — Risk Scenario 08: Insider Data Theft”Create:
RISK-008
Unauthorized Data Exfiltration by InsiderConsider:
Privileged Access
Data Access
DLP
Logging
User Behavior Monitoring
Access Reviews
Least PrivilegePerform the full assessment.
Part 24 — Add Your Own Risks
Section titled “Part 24 — Add Your Own Risks”Now identify at least five additional enterprise risks.
Possible areas include:
Software Supply Chain
CI/CD Compromise
API Security
Backup Failure
Business Email Compromise
Secrets Exposure
Third-Party Dependency
Data Retention
Shadow SaaS
AI Data LeakageDo not simply copy the names.
Write complete risk statements.
Your final register should contain at least:
13 RisksPart 25 — Identify Risk Owners
Section titled “Part 25 — Identify Risk Owners”Every risk needs an accountable owner.
Examples:
| Risk | Possible Owner |
|---|---|
| Cloud Misconfiguration | Head of Cloud Engineering |
| Phishing | CISO |
| Vendor Risk | Procurement / Business Owner |
| Application Vulnerability | Head of Engineering |
| Availability Risk | CIO |
| Privacy Risk | Privacy Officer |
The risk owner should have sufficient authority to make treatment decisions.
Part 26 — Risk Owner vs Control Owner
Section titled “Part 26 — Risk Owner vs Control Owner”Do not confuse these roles.
Risk Owner ↓Accountable for Risk
Control Owner ↓Accountable for ControlExample:
Risk:Privileged Account Compromise
Risk Owner:CISO
Controls:PAMMFAAccess ReviewsMonitoring
Control Owners:IAM TeamSOC TeamIT OperationsOne risk may depend on several controls.
Part 27 — Determine Risk Treatment
Section titled “Part 27 — Determine Risk Treatment”Review every risk and assign:
Mitigate
Avoid
Transfer
AcceptMitigate
Section titled “Mitigate”Implement additional controls.
Stop the activity creating the risk.
Transfer
Section titled “Transfer”Shift some financial or operational exposure through mechanisms such as insurance or contractual arrangements.
Accept
Section titled “Accept”Management formally accepts the residual exposure.
Part 28 — Risk Acceptance
Section titled “Part 28 — Risk Acceptance”Suppose:
Residual Risk:Moderate
Remediation Cost:₹50,00,000
Expected Business Exposure:LowManagement may decide to accept the risk.
Document:
Risk Acceptance
Business Justification
Approver
Approval Date
Expiration Date
Review DateRisk acceptance should be a governance decision.
Part 29 — Define Remediation Actions
Section titled “Part 29 — Define Remediation Actions”Avoid vague actions such as:
Improve SecurityInstead use measurable actions.
Example:
Deploy phishing-resistant MFA for all privileged identities and high-risk administrative roles.
Another:
Configure CI/CD policy checks preventing deployment of publicly accessible storage resources.
Good remediation should answer:
What?
Who?
When?
How will completion be proven?Part 30 — Remediation Tracker
Section titled “Part 30 — Remediation Tracker”Create another worksheet:
Risk Remediation TrackerUse:
| Action ID | Risk ID | Remediation | Owner | Target | Status | Evidence |
|---|
Example:
| Action ID | Risk ID | Remediation | Owner | Target | Status | Evidence |
|---|---|---|---|---|---|---|
| ACT-001 | RISK-001 | Deploy phishing-resistant MFA | IAM | 90 Days | Open | Deployment report |
Part 31 — Risk Status
Section titled “Part 31 — Risk Status”Use standardized statuses:
Open
Treatment Planned
In Progress
Risk Accepted
Monitoring
ClosedAvoid inconsistent statuses such as:
Working
Nearly Done
Looking Good
Pending MaybeStandardization enables reporting.
Part 32 — Build the Risk Matrix
Section titled “Part 32 — Build the Risk Matrix”Create a 5 × 5 risk matrix.
Use:
Likelihood →ImpactConceptually:
| Likelihood ↓ / Impact → | 1 | 2 | 3 | 4 | 5 |
|---|---|---|---|---|---|
| 5 | 5 | 10 | 15 | 20 | 25 |
| 4 | 4 | 8 | 12 | 16 | 20 |
| 3 | 3 | 6 | 9 | 12 | 15 |
| 2 | 2 | 4 | 6 | 8 | 10 |
| 1 | 1 | 2 | 3 | 4 | 5 |
This visually represents risk severity.
Part 33 — Risk Prioritization
Section titled “Part 33 — Risk Prioritization”Sort your register by:
Residual Risk Scorehighest to lowest.
Your highest risks should receive management attention first.
Example:
RISK-002 15 High
RISK-001 12 High
RISK-004 12 High
RISK-003 10 HighPart 34 — Identify Critical Risks
Section titled “Part 34 — Identify Critical Risks”Create a filter for:
Residual Rating = CriticalAsk:
-
Why is the risk still critical?
-
Are controls ineffective?
-
Is remediation underway?
-
Does leadership know?
-
Does immediate escalation make sense?
Critical residual risk should not quietly remain in a spreadsheet.
Part 35 — Identify Overdue Risks
Section titled “Part 35 — Identify Overdue Risks”Add:
Target Dateand identify:
Target Date < TodayANDStatus ≠ ClosedThese are overdue remediation actions.
GRC should monitor and escalate them.
Part 36 — Risk Aging
Section titled “Part 36 — Risk Aging”Add:
Risk Created Dateand optionally calculate:
Risk Age =Today - Risk Created DateLong-running high risks may indicate remediation problems.
Part 37 — Risk Review Frequency
Section titled “Part 37 — Risk Review Frequency”Define review frequency based on risk.
Example:
| Residual Risk | Review |
|---|---|
| Critical | Monthly |
| High | Quarterly |
| Moderate | Semiannual |
| Low | Annual |
This creates risk-based monitoring.
Part 38 — Risk Escalation
Section titled “Part 38 — Risk Escalation”Define escalation rules.
Example:
Critical Risk ↓CISO / Executive Risk Committee
High Risk Overdue ↓Security Leadership
Repeated Missed Remediation ↓Executive EscalationEscalation rules strengthen governance.
Part 39 — Create an Executive Dashboard
Section titled “Part 39 — Create an Executive Dashboard”Create a worksheet:
Risk DashboardInclude:
Total Risks
Critical Risks
High Risks
Moderate Risks
Low Risks
Overdue Risks
Accepted Risks
Risks Under TreatmentExample:
| Metric | Result |
|---|---|
| Total Risks | 13 |
| Critical | 2 |
| High | 5 |
| Moderate | 4 |
| Low | 2 |
| Overdue | 3 |
Part 40 — Risk by Domain
Section titled “Part 40 — Risk by Domain”Categorize risks into domains such as:
Identity
Cloud
Endpoint
Application
Third Party
Data Protection
Resilience
GovernanceCreate:
| Domain | Risks |
|---|---|
| Cloud | 4 |
| Identity | 3 |
| Third Party | 2 |
| Application | 2 |
| Resilience | 2 |
This helps identify concentrations.
Part 41 — Risk by Treatment
Section titled “Part 41 — Risk by Treatment”Summarize:
| Treatment | Count |
|---|---|
| Mitigate | 8 |
| Accept | 2 |
| Transfer | 2 |
| Avoid | 1 |
Leadership can see how risks are being managed.
Part 42 — Executive Risk Summary
Section titled “Part 42 — Executive Risk Summary”Write a short executive summary.
Example:
The enterprise cybersecurity risk assessment identified 13 material risks across cloud security, identity, endpoint security, third-party services, application security, and operational resilience. Two risks currently remain at Critical residual severity and require immediate management attention. Five risks remain High and have active remediation plans. Priority actions include strengthening privileged identity protection, preventing insecure cloud configurations, improving ransomware resilience, and reducing critical third-party exposure.
Keep executive reporting focused on:
What is the risk?
Why does it matter?
What are we doing?
Who owns it?
When will exposure reduce?Part 43 — Risk Register Quality Review
Section titled “Part 43 — Risk Register Quality Review”Before completing the lab, review every risk.
Verify:
-
Risk statement is clear.
-
Asset or process is identified.
-
Threat is documented.
-
Vulnerability is documented.
-
Business impact is meaningful.
-
Inherent likelihood is assigned.
-
Inherent impact is assigned.
-
Inherent score is correct.
-
Existing controls are documented.
-
Control effectiveness is evaluated.
-
Residual likelihood is assigned.
-
Residual impact is assigned.
-
Residual score is correct.
-
Risk owner is identified.
-
Treatment is selected.
-
Remediation is measurable.
-
Target date exists.
-
Status is current.
Part 44 — Common Mistakes to Avoid
Section titled “Part 44 — Common Mistakes to Avoid”Mistake 1 — Writing Issues Instead of Risks
Section titled “Mistake 1 — Writing Issues Instead of Risks”Weak:
MFA MissingBetter:
There is a risk that attackers may compromise administrative accounts due to the absence of strong MFA, resulting in unauthorized privileged access.
Mistake 2 — Scoring Before Defining Criteria
Section titled “Mistake 2 — Scoring Before Defining Criteria”Do not assign numbers without a documented methodology.
Mistake 3 — Treating Every Risk as Critical
Section titled “Mistake 3 — Treating Every Risk as Critical”If everything is critical:
Nothing is prioritized.Mistake 4 — Ignoring Existing Controls
Section titled “Mistake 4 — Ignoring Existing Controls”Inherent and residual risk should not be identical automatically.
Mistake 5 — No Risk Owner
Section titled “Mistake 5 — No Risk Owner”A risk without an owner often becomes a risk without action.
Mistake 6 — Vague Remediation
Section titled “Mistake 6 — Vague Remediation”Avoid:
Improve cloud security.
Use:
Implement policy-as-code validation preventing public cloud storage deployments by Q4.
Mistake 7 — Confusing Risk Acceptance With Ignoring Risk
Section titled “Mistake 7 — Confusing Risk Acceptance With Ignoring Risk”Accepted risks still require:
Documentation
Approval
Monitoring
Periodic ReviewPart 45 — Final Deliverables
Section titled “Part 45 — Final Deliverables”At the end of the lab, your workbook should contain at least:
01 — Asset Inventory
02 — Risk Methodology
03 — Enterprise Risk Register
04 — Risk Remediation Tracker
05 — Risk Matrix
06 — Risk DashboardYour Enterprise Risk Register should contain:
13+ Risk Scenarios
Inherent Risk Scores
Existing Controls
Control Effectiveness
Residual Risk Scores
Risk Owners
Treatment Decisions
Remediation Actions
Target Dates
Current StatusLab Validation Checklist
Section titled “Lab Validation Checklist”Before marking the lab complete:
-
Created asset inventory.
-
Identified critical assets.
-
Defined likelihood scale.
-
Defined impact scale.
-
Defined risk-rating thresholds.
-
Created 5 × 5 risk matrix.
-
Created enterprise risk register.
-
Documented at least 13 risks.
-
Used structured risk statements.
-
Calculated inherent risk.
-
Identified existing controls.
-
Evaluated control effectiveness.
-
Calculated residual risk.
-
Assigned risk owners.
-
Selected risk treatments.
-
Created remediation actions.
-
Defined target dates.
-
Created remediation tracker.
-
Identified overdue risks.
-
Created executive dashboard.
-
Prepared executive risk summary.
Expected Skills After This Lab
Section titled “Expected Skills After This Lab”After completing this exercise, you should be comfortable performing the workflow:
Understand Business ↓Identify Assets ↓Identify Risk ↓Write Risk Scenario ↓Assess Inherent Risk ↓Identify Controls ↓Evaluate Controls ↓Assess Residual Risk ↓Select Treatment ↓Assign Owner ↓Plan Remediation ↓Monitor ↓ReportThis workflow represents one of the foundational responsibilities of an enterprise GRC Analyst.
Real-World GRC Perspective
Section titled “Real-World GRC Perspective”In a real organization, your risk register may contain hundreds or thousands of risks.
The register may also connect to:
Business Assets ↓Risks ↓Controls ↓Policies ↓Compliance Requirements ↓Findings ↓Remediation ↓EvidenceThis is why the risk register is more than a spreadsheet.
It becomes part of the organization’s broader GRC system of record.
Mission Complete
Section titled “Mission Complete”You have built the foundation of an Enterprise Cybersecurity Risk Register.
You have practiced how GRC teams move from:
Technical Problem ↓Risk Scenario ↓Business Impact ↓Risk Score ↓Controls ↓Residual Risk ↓Management Decision ↓RemediationThis is the transition from simply identifying security problems to managing cybersecurity as enterprise risk.
What’s Next?
Section titled “What’s Next?”➡️ Lab 02 — Perform a Third-Party Security Risk Assessment
In the next lab, you will take the role of a Third-Party Risk / GRC Analyst and assess a fictional SaaS provider before the organization approves it for enterprise use.
You will perform the complete vendor assessment lifecycle:
Vendor Request ↓Business Intake ↓Inherent Risk Assessment ↓Vendor Tiering ↓Security Due Diligence ↓Evidence Review ↓SOC 2 Review ↓ISO Certification Review ↓Control Gap Analysis ↓Residual Risk ↓Vendor Findings ↓Remediation Requirements ↓Risk RecommendationYour final deliverable will be a professional Third-Party Security Risk Assessment Report containing the vendor’s risk classification, security findings, residual risk, remediation requirements, and approval recommendation.