Lab 01 — Build an AI-Assisted Enterprise Risk Assessment
Welcome to your first hands-on lab in:
AI for GRC Professionals
In this lab, you will perform an end-to-end enterprise cybersecurity risk assessment.
You will use AI to help you:
UnderstandBusiness Context
↓
IdentifyAssets and Threats
↓
DevelopRisk Scenarios
↓
AnalyzeLikelihood and Impact
↓
ReviewExisting Controls
↓
DetermineCandidate Residual Risk
↓
DevelopTreatment OptionsBut throughout the lab, remember:
AISupports Analysis
↓
GRC AnalystValidates
↓
Risk OwnerMakes the DecisionMission Information
Section titled “Mission Information”Mission
Section titled “Mission”You have joined:
CloudNova Technologiesas a:
CybersecurityGRC AnalystCloudNova operates a SaaS platform used by enterprise customers.
The organization is rapidly expanding its cloud environment and has asked the GRC team to perform a cybersecurity risk assessment of its production platform.
Your mission is to:
Identify
Analyze
Document
Evaluate
Treatthe most important cybersecurity risks affecting the platform.
You will use AI as an:
Risk AnalysisAssistantbut all material conclusions must be validated by you.
Scenario
Section titled “Scenario”CloudNova provides a cloud-hosted customer management platform.
The environment is hosted primarily in:
AWSThe production platform contains:
Customer Information
Application Data
Authentication Data
Business Records
System LogsThe platform is considered:
Business Criticalbecause customers depend on it for daily operations.
CloudNova currently has:
200 Employees
45 Engineers
12 Cloud Administrators
3 Security Engineers
1 GRC AnalystEnvironment Overview
Section titled “Environment Overview”The production architecture includes:
Internet Users ↓Web Application ↓Application Load Balancer ↓Application Servers ↓Managed Database ↓Object StorageAdministrative access is performed through:
Corporate Identity Provider ↓Cloud Roles ↓AWS Production AccountsSecurity services include:
Cloud Logging
Endpoint Protection
Vulnerability Scanning
MFA
Security MonitoringHowever, several recent observations have raised concerns.
Current Observations
Section titled “Current Observations”The following information was identified during an internal review.
Observation 1 — Privileged MFA
Section titled “Observation 1 — Privileged MFA”CloudNova has:
12PrivilegedCloud AdministratorsThree privileged administrator accounts currently do not have MFA enforced.
Observation 2 — Vulnerability Management
Section titled “Observation 2 — Vulnerability Management”The production environment contains:
8 CriticalVulnerabilitiesthat have remained unresolved for more than:
45 DaysObservation 3 — Public Storage
Section titled “Observation 3 — Public Storage”One cloud storage bucket containing:
Customer Export Fileswas identified as publicly accessible.
The exposure was corrected after discovery.
Observation 4 — Logging
Section titled “Observation 4 — Logging”Cloud activity logs are enabled.
However:
CentralizedSecurity Monitoringdoes not currently cover all production accounts.
Observation 5 — Backup
Section titled “Observation 5 — Backup”Daily database backups are configured.
However, the organization has not performed a full:
Disaster RecoveryRestore Testduring the last 12 months.
Observation 6 — Third-Party Access
Section titled “Observation 6 — Third-Party Access”A managed service provider has administrator access to selected production systems.
The vendor accounts are manually reviewed.
There is no formal:
Privileged AccessManagementplatform.
Lab Objectives
Section titled “Lab Objectives”By completing this lab, you will learn how to:
-
define business context before assessing risk.
-
identify critical assets.
-
distinguish threats, vulnerabilities and risks.
-
develop structured cybersecurity risk scenarios.
-
use AI to support risk discovery.
-
prevent AI from inventing unsupported facts.
-
analyze existing controls.
-
identify missing information.
-
perform qualitative likelihood analysis.
-
perform qualitative impact analysis.
-
determine inherent risk.
-
analyze control effectiveness.
-
estimate candidate residual risk.
-
develop risk treatment options.
-
create a professional enterprise risk register.
-
prepare an executive risk summary.
-
validate AI-generated risk analysis.
Prerequisites
Section titled “Prerequisites”Before starting, you should understand:
Risk
Threat
Vulnerability
Control
Likelihood
Impact
Inherent Risk
Residual Risk
Risk TreatmentYou should also have completed:
05 — AI-Assisted Risk Assessmentand Risk Register ManagementTools Required
Section titled “Tools Required”You may use:
Generative AI Assistant
Spreadsheet Software
Markdown / Text EditorOptional:
Pythonfor risk-register analysis.
Lab Artifacts
Section titled “Lab Artifacts”By the end of this lab, you should create:
01 Business Context
02 Asset Inventory
03 Threat Register
04 Risk Scenario Register
05 Risk Assessment Worksheet
06 Enterprise Risk Register
07 Risk Treatment Plan
08 Executive Risk SummaryPart 1 — Understand the Business Context
Section titled “Part 1 — Understand the Business Context”Risk does not exist in isolation.
Before asking:
What CouldGo Wrong?you first need to understand:
What Mattersto the Business?Step 1 — Identify Business Objectives
Section titled “Step 1 — Identify Business Objectives”For CloudNova, candidate objectives include:
Provide ReliableCustomer Service
Protect Customer Data
Maintain ProductionAvailability
Meet ContractualCommitments
Protect CompanyReputationCreate:
Business_Context.mdwith:
Organization
Business Service
Business Objectives
Critical Processes
Critical Data
Major DependenciesStep 2 — Ask AI to Organize the Context
Section titled “Step 2 — Ask AI to Organize the Context”Use:
ROLE
Act as a cybersecurityGRC risk analysis assistant.
CONTEXT
CloudNova operatesa business-criticalSaaS platform hostedin AWS.
INPUT
Use only the suppliedbusiness and technicalinformation.
TASK
Identify:
Business Objectives
Critical Services
Critical Data
Technology Dependencies
Third-Party Dependencies
Missing Information
CONSTRAINTS
Do not inventbusiness facts.
Mark unknown informationas:
Needs ValidationValidation Checkpoint
Section titled “Validation Checkpoint”Review every AI-generated statement.
Ask:
Was ThisProvided?If not:
Remove It
or
Mark ItNeeds ValidationExpected Outcome
Section titled “Expected Outcome”You should have a structured view similar to:
| Category | Item |
|---|---|
| Business Service | CloudNova SaaS Platform |
| Criticality | Business Critical |
| Primary Cloud | AWS |
| Critical Data | Customer information |
| Identity Dependency | Corporate Identity Provider |
| Third Party | Managed Service Provider |
| Monitoring | Partial centralized coverage |
| Recovery | Backups exist, restore test overdue |
Part 2 — Build the Asset Inventory
Section titled “Part 2 — Build the Asset Inventory”Risk affects something of value.
These are:
AssetsStep 3 — Identify Assets
Section titled “Step 3 — Identify Assets”From the scenario, identify:
Customer Data
Web Application
Application Servers
Production Database
Object Storage
Cloud Accounts
Privileged Identities
Security Logs
Backups
Identity ProviderStep 4 — Create Asset Inventory
Section titled “Step 4 — Create Asset Inventory”Create:
Asset_Inventory.csvwith:
| Asset ID | Asset | Type | Business Criticality | Data | Owner |
|---|---|---|---|---|---|
| AST-001 | SaaS Platform | Application | Critical | Customer Data | TBD |
| AST-002 | Production Database | Database | Critical | Customer Data | TBD |
| AST-003 | Cloud Admin Accounts | Identity | Critical | Administrative Access | TBD |
Do not invent owners.
Use:
TBDwhere information is unavailable.
Step 5 — Ask AI to Identify Missing Assets
Section titled “Step 5 — Ask AI to Identify Missing Assets”Prompt:
Review the suppliedarchitecture and asset list.
Identify assetsthat are explicitlypresent in the scenariobut missing fromthe current inventory.
Do not inferassets that werenot described.Part 3 — Identify Threats
Section titled “Part 3 — Identify Threats”A threat is something capable of causing harm.
Step 6 — Build Threat Register
Section titled “Step 6 — Build Threat Register”Candidate threats include:
External Attacker
Credential Theft
Malicious Insider
Ransomware
Cloud Misconfiguration
Vulnerability Exploitation
Third-Party Compromise
Service FailureCreate:
Threat_Register.csvwith:
| Threat ID | Threat | Relevant Assets | Evidence / Basis |
|---|---|---|---|
| THR-001 | Credential compromise | Privileged identities | MFA gaps |
| THR-002 | External exploitation | Production servers | Critical vulnerabilities |
| THR-003 | Unauthorized data access | Object storage | Public bucket finding |
Important
Section titled “Important”Do not confuse:
Threatwith:
RiskExample:
Threat:External AttackerRisk:
An external attackercould exploit anunpatched productionsystem and gainunauthorized access,resulting in customerdata exposure orservice disruption.Part 4 — Identify Vulnerabilities and Risk Conditions
Section titled “Part 4 — Identify Vulnerabilities and Risk Conditions”Step 7 — Build Condition Register
Section titled “Step 7 — Build Condition Register”Create:
Risk_Conditions.csvExample:
| Condition ID | Condition | Source |
|---|---|---|
| CON-001 | 3 privileged accounts without enforced MFA | Observation 1 |
| CON-002 | 8 critical vulnerabilities older than 45 days | Observation 2 |
| CON-003 | Public storage exposure occurred | Observation 3 |
| CON-004 | Incomplete centralized monitoring coverage | Observation 4 |
| CON-005 | DR restore test not completed in 12 months | Observation 5 |
| CON-006 | Third-party admin access lacks formal PAM | Observation 6 |
Step 8 — Distinguish Issue from Risk
Section titled “Step 8 — Distinguish Issue from Risk”Example:
3 AdministratorAccounts Lack MFAis:
A CurrentControl GapIt is not yet the complete risk statement.
Part 5 — Generate Candidate Risk Scenarios
Section titled “Part 5 — Generate Candidate Risk Scenarios”Now use AI to combine:
Asset+Threat+Condition+ImpactStep 9 — Risk Discovery Prompt
Section titled “Step 9 — Risk Discovery Prompt”Use:
ROLE
Act as a cybersecurityrisk analysis assistant.
CONTEXT
CloudNova operatesa business-criticalAWS-hosted SaaS platform.
INPUT
Use only:
Business Context
Asset Inventory
Threat Register
Risk Conditions
TASK
Identify plausiblecybersecurity risk scenarios.
For each scenario provide:
Risk ID
Asset
Threat
Condition
Risk Event
Potential Business Impact
Existing Controls
Missing Information
CONSTRAINTS
Do not inventcontrols.
Do not inventincidents.
Do not assignfinal risk ratings.
Clearly identifyassumptions.Step 10 — Review Candidate Risks
Section titled “Step 10 — Review Candidate Risks”You should identify risks similar to:
RISK-001 — Privileged Account Compromise
Section titled “RISK-001 — Privileged Account Compromise”A malicious actorcould compromise aprivileged administratoraccount that does nothave MFA enforced,gain unauthorized accessto production cloudresources and exposeor modify customer data.RISK-002 — Critical Vulnerability Exploitation
Section titled “RISK-002 — Critical Vulnerability Exploitation”An external attackercould exploit unresolvedcritical vulnerabilitiesin production systems,resulting in unauthorizedaccess, service disruptionor data compromise.RISK-003 — Cloud Storage Exposure
Section titled “RISK-003 — Cloud Storage Exposure”A cloud storagemisconfiguration couldexpose customer exportfiles to unauthorizedinternet users,resulting in customerdata disclosure.RISK-004 — Inadequate Security Monitoring
Section titled “RISK-004 — Inadequate Security Monitoring”Malicious activitywithin an unmonitoredproduction accountcould remain undetectedfor an extended period,increasing the potentialimpact of a securityincident.RISK-005 — Recovery Failure
Section titled “RISK-005 — Recovery Failure”A major productionfailure or destructivecybersecurity eventcould require restorationfrom backup, but recoverymay take longer thanexpected because thefull restore processhas not recentlybeen validated.RISK-006 — Third-Party Privileged Access
Section titled “RISK-006 — Third-Party Privileged Access”Compromise or misuseof a managed serviceprovider administratoraccount could resultin unauthorized accessto production systemsbecause privilegedthird-party access isnot governed througha formal PAM process.Step 11 — Validate Each Risk
Section titled “Step 11 — Validate Each Risk”For every risk, verify:
Threat Exists?
Asset Exists?
Condition Exists?
Impact Is Plausible?
Control Was Actually Provided?Remove unsupported statements.
Part 6 — Define the Risk Assessment Methodology
Section titled “Part 6 — Define the Risk Assessment Methodology”For this lab, use a simple:
5 × 5Risk MatrixLikelihood Scale
Section titled “Likelihood Scale”| Score | Likelihood | Definition |
|---|---|---|
| 1 | Rare | Event is highly unlikely |
| 2 | Unlikely | Event could occur but is not expected |
| 3 | Possible | Event could reasonably occur |
| 4 | Likely | Event is expected to occur under current conditions |
| 5 | Almost Certain | Event is highly likely or repeatedly expected |
Impact Scale
Section titled “Impact Scale”| Score | Impact | Definition |
|---|---|---|
| 1 | Insignificant | Minimal business impact |
| 2 | Minor | Limited operational or business impact |
| 3 | Moderate | Noticeable business, customer or operational impact |
| 4 | Major | Significant operational, financial, customer or compliance impact |
| 5 | Severe | Critical enterprise impact |
Risk Calculation
Section titled “Risk Calculation”Likelihood ×Impact =Risk ScoreRisk Rating
Section titled “Risk Rating”| Score | Rating |
|---|---|
| 1–4 | Low |
| 5–9 | Medium |
| 10–16 | High |
| 17–25 | Critical |
Important Lab Rule
Section titled “Important Lab Rule”AI may help:
Analyze Factorsbut you must assign the final scores for the lab.
Part 7 — Assess Inherent Risk
Section titled “Part 7 — Assess Inherent Risk”Inherent risk asks:
What Is the RiskBefore ConsideringExisting Controls?Step 12 — Analyze Likelihood Factors
Section titled “Step 12 — Analyze Likelihood Factors”For each risk, consider:
Exposure
Threat Capability
Existing Condition
Attack Surface
Historical Information
TechnologyDo not invent incident history.
AI Likelihood Prompt
Section titled “AI Likelihood Prompt”Using the suppliedrisk scenario andthe approved likelihoodscale:
Identify evidencethat could supporteach relevant likelihoodlevel.
Identify missinginformation.
Do not selectthe final likelihood.Step 13 — Select Likelihood
Section titled “Step 13 — Select Likelihood”Example for RISK-001:
Condition:3 privileged accountswithout MFA
Potential Threat:Credential compromise
Exposure:Production administrative accessYou might select:
Likelihood = 4Likelybut document your reasoning.
Step 14 — Analyze Impact
Section titled “Step 14 — Analyze Impact”Use:
Using the suppliedrisk scenario andthe approved impactscale:
Identify potentialbusiness impact across:
Confidentiality
Integrity
Availability
Customer Impact
Operational Impact
Compliance Impact
Do not exaggerateimpact.
Do not assignthe final rating.Step 15 — Select Impact
Section titled “Step 15 — Select Impact”For RISK-001, you may determine:
Impact = 5Severeif privileged access could materially affect production and customer data.
Again, record the justification.
Step 16 — Calculate Inherent Risk
Section titled “Step 16 — Calculate Inherent Risk”Example:
Likelihood = 4
Impact = 5
Inherent Risk=20
Rating:CriticalPart 8 — Review Existing Controls
Section titled “Part 8 — Review Existing Controls”Now identify controls already present.
Step 17 — Build Control Register
Section titled “Step 17 — Build Control Register”From the scenario, existing controls include:
Corporate Identity Provider
MFA
Cloud Logging
Endpoint Protection
Vulnerability Scanning
Daily Database Backups
Manual Vendor Access ReviewCreate:
Control_Register.csv| Control ID | Control | Type | Related Risk | Evidence |
|---|---|---|---|---|
| CTRL-001 | MFA | Preventive | RISK-001 | Configuration |
| CTRL-002 | Vulnerability scanning | Detective | RISK-002 | Scan report |
| CTRL-003 | Cloud logging | Detective | RISK-004 | Cloud log config |
| CTRL-004 | Daily backups | Recovery | RISK-005 | Backup records |
Step 18 — Evaluate Control Limitations
Section titled “Step 18 — Evaluate Control Limitations”Example:
Control:MFA
Limitation:Not enforcedfor all privilegedaccountsAnother:
Control:Logging
Limitation:Not centrally monitoredacross all productionaccountsStep 19 — Ask AI for Control Coverage Analysis
Section titled “Step 19 — Ask AI for Control Coverage Analysis”For each validatedrisk scenario:
Review the suppliedcontrols.
Identify:
Preventive Controls
Detective Controls
Responsive Controls
Recovery Controls
Control Limitations
Potential Coverage Gaps
Do not assumecontrol effectiveness.Part 9 — Assess Residual Risk
Section titled “Part 9 — Assess Residual Risk”Residual risk considers:
Risk ↓Existing Controls ↓Remaining ExposureStep 20 — Reassess Likelihood
Section titled “Step 20 — Reassess Likelihood”Consider whether controls reduce:
Probabilityof the scenario.
Example:
MFA exists for many privileged users, but three accounts remain uncovered.
Likelihood may reduce from:
4to:
3depending on your assessment.
Step 21 — Reassess Impact
Section titled “Step 21 — Reassess Impact”Controls may or may not reduce impact.
Example:
Monitoring may help reduce:
Incident Durationbut may not prevent the initial compromise.
Step 22 — Calculate Residual Risk
Section titled “Step 22 — Calculate Residual Risk”Example:
Residual Likelihood:3
Residual Impact:5
Residual Score:15
Residual Rating:HighPart 10 — Build the Enterprise Risk Register
Section titled “Part 10 — Build the Enterprise Risk Register”Create:
Enterprise_Risk_Register.csvwith:
| Field |
|---|
| Risk ID |
| Risk Title |
| Risk Statement |
| Asset |
| Threat |
| Condition |
| Business Impact |
| Existing Controls |
| Control Limitations |
| Inherent Likelihood |
| Inherent Impact |
| Inherent Score |
| Inherent Rating |
| Residual Likelihood |
| Residual Impact |
| Residual Score |
| Residual Rating |
| Risk Owner |
| Treatment |
| Target Date |
| Status |
Example Entry
Section titled “Example Entry”Risk ID:RISK-001
Title:Privileged CloudAccount Compromise
Risk Statement:A malicious actorcould compromise aprivileged accountwithout MFA enforcement,gain unauthorized accessto production resourcesand expose or modifycustomer information.
Asset:AWS Production Environment
Threat:Credential Compromise
Condition:3 privilegedadministrator accountswithout MFA
Inherent Risk:20 — Critical
Existing Controls:Corporate IdPPartial MFACloud Logging
Residual Risk:15 — High
Owner:TBDPart 11 — Develop Risk Treatment Options
Section titled “Part 11 — Develop Risk Treatment Options”Common treatment approaches:
Avoid
Reduce
Transfer
AcceptFor most risks in this lab, reduction is likely to be relevant.
Step 23 — Generate Treatment Options
Section titled “Step 23 — Generate Treatment Options”Prompt:
For the validatedrisk scenario:
Generate candidaterisk treatment options.
Classify them as:
Avoid
Reduce
Transfer
Accept
For each provide:
Action
Expected Benefit
Limitation
Dependency
Potential Evidenceof Completion
Do not selectthe final treatment.
Do not acceptthe risk.Example — RISK-001
Section titled “Example — RISK-001”Potential reduction actions:
Enforce MFAfor all privilegedaccounts
Implement PAM
Remove standingadministrative privileges
Introduce time-limitedprivileged access
Improve privilegedactivity monitoringStep 24 — Build Treatment Plan
Section titled “Step 24 — Build Treatment Plan”Create:
Risk_Treatment_Plan.csvwith:
| Risk ID | Action | Owner | Priority | Target Date | Evidence | Status |
|---|---|---|---|---|---|---|
| RISK-001 | Enforce MFA for all admins | TBD | High | TBD | IAM config | Proposed |
| RISK-001 | Evaluate PAM implementation | TBD | Medium | TBD | PAM design | Proposed |
Part 12 — Identify Risk Owners
Section titled “Part 12 — Identify Risk Owners”Risk should not automatically be owned by:
GRCThe risk owner should be someone with:
BusinessorOperational Authorityto manage the exposure.
For this lab, where ownership is unknown, use:
TBDThen identify the likely organizational role requiring confirmation.
Part 13 — Build Risk Treatment Priorities
Section titled “Part 13 — Build Risk Treatment Priorities”A simple model:
Critical ↓Immediate Management Attention
High ↓Prioritized Remediation
Medium ↓Planned Treatment
Low ↓MonitorUse your organization’s approved methodology in real environments.
Part 14 — Perform Risk Register Quality Review
Section titled “Part 14 — Perform Risk Register Quality Review”Ask AI:
Review the suppliedrisk register.
Identify:
Duplicate Risks
Weak Risk Statements
Missing Owners
Missing Controls
Missing Treatments
Missing Review Dates
Inconsistent Ratings
Unsupported Assumptions
Do not changethe register.Validation Checkpoint
Section titled “Validation Checkpoint”For every issue flagged by AI:
VerifyBefore Changingthe Risk RegisterPart 15 — Risk Correlation
Section titled “Part 15 — Risk Correlation”Now look across the risks.
You may notice:
RISK-001Privileged MFA
RISK-004Monitoring Gaps
RISK-006Vendor Privileged Accessall relate to:
IdentityandPrivileged AccessThis may indicate a broader:
Identity GovernanceRisk ThemeStep 25 — Theme Analysis
Section titled “Step 25 — Theme Analysis”Prompt:
Analyze the validatedrisk register.
Identify commonrisk themes.
For each themeprovide:
Related Risk IDs
Common Assets
Common Controls
Common Conditions
Potential Systemic Issue
Do not createa new enterpriserisk automatically.Part 16 — Executive Risk Summary
Section titled “Part 16 — Executive Risk Summary”Executives should not receive the entire technical worksheet first.
They need:
What Isthe Risk?
Why DoesIt Matter?
How SignificantIs It?
What AreWe Doing?
What DecisionIs Required?Step 26 — Create Executive Summary
Section titled “Step 26 — Create Executive Summary”Use:
ROLE
Act as an executivecyber risk reportingassistant.
INPUT
Use only thevalidated enterpriserisk register.
TASK
Prepare a conciseexecutive risk summary.
Include:
Top Risks
Business Impact
Residual Risk
Risk Trendsif available
Key Control Gaps
Treatment Priorities
Decisions Required
CONSTRAINTS
Do not changerisk ratings.
Do not inventfinancial impact.
Do not exaggeraterisk.Example Executive Summary
Section titled “Example Executive Summary”CloudNova's mostsignificant identifiedcybersecurity exposuresrelate to privilegedaccess, unresolvedcritical vulnerabilitiesand production monitoring.
The highest residualrisk concerns privilegedcloud access, wherethree administratoraccounts currentlylack enforced MFA.
Additional materialexposure exists fromcritical vulnerabilitiesthat have remainedunresolved beyondthe expected remediationperiod.
Management shouldprioritize privilegedaccess remediation,critical vulnerabilityresolution and completeproduction securitymonitoring coverage.Part 17 — Create Risk Heatmap Data
Section titled “Part 17 — Create Risk Heatmap Data”Prepare:
Risk_Heatmap.csvwith:
| Risk | Likelihood | Impact | Score | Rating |
|---|---|---|---|---|
| RISK-001 | 3 | 5 | 15 | High |
| RISK-002 | 3 | 4 | 12 | High |
| RISK-003 | 2 | 5 | 10 | High |
Use only your validated residual ratings.
Part 18 — Challenge the Assessment
Section titled “Part 18 — Challenge the Assessment”A mature GRC analyst challenges their own conclusions.
Ask AI:
Challenge thecurrent risk assessment.
Identify:
Unsupported Assumptions
Missing Evidence
Possible Overstatement
Possible Understatement
Alternative Scenarios
Controls That MayHave Been Missed
Questions forRisk Owners
Do not changethe official ratings.Step 27 — Document Challenge Results
Section titled “Step 27 — Document Challenge Results”Create:
Risk_Assessment_Review.mdDocument:
AI Challenge
Analyst Response
Accepted Change
Rejected Change
ReasonThis provides:
TraceabilityPart 19 — Final Validation
Section titled “Part 19 — Final Validation”Before completing the lab, verify every risk.
For each ask:
01 Is the asset real?
02 Is the threat plausible?
03 Is the condition supported?
04 Is the risk event clear?
05 Is business impact plausible?
06 Are controls actually present?
07 Are control limitations documented?
08 Are scores based on methodology?
09 Is residual risk justified?
10 Is the treatment actionable?
11 Is ownership identified or TBD?
12 Did AI invent anything?Expected Final Risk Register
Section titled “Expected Final Risk Register”Your final register should contain approximately:
5–8Well-DefinedCybersecurity RisksDo not create:
50 Generic RisksQuality is more important than quantity.
Portfolio Deliverables
Section titled “Portfolio Deliverables”At the end of this mission, keep:
01 Business_Context.md
02 Asset_Inventory.csv
03 Threat_Register.csv
04 Risk_Conditions.csv
05 Risk_Scenario_Register.csv
06 Control_Register.csv
07 Risk_Assessment_Worksheet.csv
08 Enterprise_Risk_Register.csv
09 Risk_Treatment_Plan.csv
10 Risk_Assessment_Review.md
11 Executive_Risk_Summary.md
12 Risk_Heatmap.csvPortfolio Structure
Section titled “Portfolio Structure”Recommended folder:
Lab 01 — AI-Assisted Enterprise Risk Assessment│├── 01 Business Context├── 02 Asset Inventory├── 03 Threat Register├── 04 Risk Conditions├── 05 Risk Scenarios├── 06 Control Register├── 07 Risk Assessment├── 08 Enterprise Risk Register├── 09 Risk Treatment Plan├── 10 Assessment Review├── 11 Executive Summary└── 12 Risk HeatmapMission Success Criteria
Section titled “Mission Success Criteria”You have successfully completed the lab when:
-
business objectives are documented.
-
critical assets are identified.
-
threats are separated from risks.
-
current control gaps are documented.
-
at least five structured risk scenarios exist.
-
inherent risk is assessed.
-
existing controls are documented.
-
residual risk is assessed.
-
treatment options exist.
-
risk owners are identified or marked TBD.
-
every material conclusion is traceable to the scenario.
-
AI assumptions have been challenged.
-
an executive summary has been produced.
Knowledge Check
Section titled “Knowledge Check”-
Why should business context be understood before identifying risks?
-
What is the difference between a threat and a risk?
-
What is the difference between a vulnerability and a risk?
-
Why is missing MFA not itself a complete risk statement?
-
What elements make up a strong risk scenario?
-
Why should AI-generated risks be considered candidate risks?
-
What is inherent risk?
-
What is residual risk?
-
Why does the existence of a control not prove control effectiveness?
-
What is the purpose of a risk register?
-
Why should GRC not automatically own every risk?
-
What are the four common risk treatment approaches?
-
Why should AI not assign final risk acceptance?
-
What is risk correlation?
-
What is a systemic risk theme?
-
Why should risk assessments be challenged?
-
Why must assumptions be documented?
-
Why should risk ratings follow an approved methodology?
-
Why is executive risk reporting different from analyst reporting?
-
What role should AI play in enterprise risk assessment?
Key Takeaways
Section titled “Key Takeaways”The risk-assessment process is:
Business Context ↓Assets ↓Threats ↓Conditions ↓Risk Scenarios ↓Likelihood ↓Impact ↓Inherent Risk ↓Controls ↓Residual Risk ↓Treatment ↓MonitoringAI can accelerate:
Risk Discovery
Risk Writing
Data Organization
Control Analysis
Treatment Analysis
Theme Detection
ReportingBut:
AI-Generated Risk ≠Validated Riskand:
AI Risk Score ≠Risk Owner Decisionand:
Control Exists ≠Control Is Effectiveand:
No Evidence ≠No RiskThe professional workflow remains:
AIAnalyzes
↓
GRC AnalystValidates
↓
Risk OwnerEvaluates
↓
Authorized AuthorityMakes the DecisionCareer Connection
Section titled “Career Connection”This lab mirrors activities performed by:
GRC Analysts
Cyber Risk Analysts
Technology Risk Analysts
Cloud Risk Analysts
Security Assurance Analysts
Risk Consultants
GRC ConsultantsDuring an interview, you should be able to explain:
How YouIdentified the Risk
Why It Matters
Which ControlsApply
How YouAssessed It
What TreatmentYou Recommended
How AISupported the ProcessThe strongest portfolio outcome is not simply a spreadsheet.
It is demonstrating that you understand:
Business ↓Technology ↓Threat ↓Risk ↓Control ↓DecisionWhat’s Next?
Section titled “What’s Next?”➡️ Next: Lab 02 — AI-Assisted Policy Review and Gap Analysis
In the next lab, you will move from:
EnterpriseRisk Assessmentto:
EnterprisePolicy GovernanceYou will receive a fictional security policy and use AI to:
Extract Requirements
Review Policy Structure
Identify Ambiguous Language
Identify Missing Requirements
Perform Gap Analysis
Map Requirementsto Controls
Draft Improvements
Validate AI RecommendationsYour final portfolio artifacts will include:
Policy Review Report
Requirement Register
Policy Gap Register
Policy-to-Control Mapping
Updated Policy Draft➡️ Next: Lab 02 — AI-Assisted Policy Review and Gap Analysis