Skip to main content
Guidance

Risk management

How to understand and manage the cyber security risks for your organisation.

Page 3 of 15

Cyber security risk management framework

Help understanding what a good approach to risk management looks like, and what approaches to cyber security risk management are right for your organisation.







If you have chosen to manage the risks you have identified by treating them using technical or non-technical controls, then it is important that you and those who own cyber security risks within your organisation are confident that those controls will work as you expect them to, and that they will continue to do so throughout the life of the system or service you are using. This confidence is known as ‘security assurance’, ‘technical assurance’ or simply ‘assurance’.

You will need to describe and communicate how you will gain assurance (and maintain it for the controls you recommend) when you present your recommendations to decision makers. For further information refer to the section on how to gain and maintain assurance for your risk treatments.

It is not possible to completely eliminate or treat all risk. When you treat cyber security risks using controls there will always be a risk or a number of risks that are left over, and these are referred to as 'residual risks'. These residual risks themselves also need to be managed.

The amount of risk analysis carried out needs to be proportionate to the risk challenge you are facing, and if your approach is not providing you with information that helps you identify and manage cyber security risks, then you should stop and consider whether you have done enough, or whether you need to try something else to elicit further information.

The cyber security risk management recommendations you make should be delivered to the appropriate decision makers, at the right time and in the right format. In all cases the risks you assess and recommendations you make should be traceable to what the business is doing and cares about. Your recommendations should be feasible and fit with your decision maker’s constraints, but it should also be clear to them what risks they would continue to take, in other words what residual risk would be left over, if they were to accept your recommendations. These and the other analyses and decisions you have made should be appropriately documented to maintain traceability. These documents might include:

  • a risk register: this communicates and prioritises risks that have been identified to decision makers and other stakeholders
  • a cyber security risk management plan: this sets out how cyber security risks will be managed and describes those controls that will be implemented to treat identified risks
  • an assurance plan: this sets out how assurance in the controls used to treat identified risks will be gained and maintained throughout the whole life of a system or service
  • a statement of residual risk: this identifies, for decision makers, the risks that are left over after you have treated identified risks, so that they can make informed decisions about how they should be managed

You should be able to justify and defend your recommendations. Any claims you make, or information you provide should be supported by good arguments and evidence. You should understand that controls are only useful when they are addressing identified risks. If your technique does not enable you to do this, then you should consider taking and alternative approach.

Considerations:

  • Make the most effective use of different sources of data and information.
  • Quantitative information and approaches may be useful in developing cost-benefit analyses to inform decisions about potential controls.
  • Be conscious of the limited utility of statements and labels like ‘high’, ‘medium’ or ‘low’ without setting them within a meaningful technology and/or business context. Your understanding of high may not be the same as your audience.
  • Be aware of the potential influence of unconscious bias which may skew some of the inputs on which you base your analysis.



Published

Reviewed

Version

2.0