High School AdvancedModule A15Governance and Automation

Advanced Module 15

Risk Management and Compliance

Cybersecurity teams do more than identify technical weaknesses. They help organizations decide what matters, how serious a risk is, which controls reduce it, who owns the decision, what evidence is trustworthy, and which actions should happen first.

A15 teaches defensive risk analysis using fictional organizations, synthetic evidence, safe control reviews, governance records, and business-focused decision making.

Lessons

10

A15.1 through A15.10

Module Test

25 Q

One Advanced assessment

Portfolio Outcome

1

Risk Register and Leadership Recommendation

Primary Lens

Risk

Business decisions backed by security evidence

Main Question

How should security teams turn technical uncertainty into a business decision?

Risk management is not a contest to create the most dramatic score. The goal is to describe uncertainty clearly, connect it to business impact, evaluate the controls that already exist, identify what evidence supports the conclusion, and recommend a treatment that an accountable owner can act on.

Safety and Ethics Boundary

Risk analysis uses authorized evidence—not unsafe testing

Every A15 scenario is fictional and defensive. Students evaluate synthetic risk records, architecture findings, control evidence, audits, exception records, supplier information, and leadership decisions. No lesson requires exploiting vulnerabilities, scanning real systems, collecting credentials, accessing private organizational information, bypassing controls, or testing third-party systems without authorization.

Professional Workflow

A Five-Part Risk Decision Pattern

This is a module-level orientation, not a rigid pattern every lesson must repeat. Individual lessons will use the structure that best fits the topic: risk scenarios, registers, control reviews, evidence analysis, exception decisions, supplier reviews, or leadership communication.

1

Frame the decision

Identify the business service, asset, data, dependency, stakeholder, decision scope, and reason the risk review exists.

Evidence: Business context, service inventory, data classification, owner, architecture notes.

2

Analyze the risk

Describe the threat event, exposure condition, impact, likelihood, uncertainty, and existing control environment.

Evidence: Risk scenario, dependency map, incident history, control evidence, architecture findings.

3

Evaluate controls and evidence

Determine which controls reduce the risk and whether evidence shows those controls are designed and operating as intended.

Evidence: Control owner, expected outcome, test evidence, monitoring, audit evidence, source freshness.

4

Choose a treatment

Recommend remediation, mitigation, transfer, avoidance, acceptance, or another governed treatment based on business need and residual risk.

Evidence: Treatment options, cost/effort, business impact, exception state, risk-owner decision.

5

Communicate and review

Record ownership, due dates, decision state, residual risk, leadership recommendation, evidence requirements, and triggers that reopen the risk.

Evidence: Risk register, leadership brief, exception expiry, review cadence, closure evidence.

Learning Outcomes

Six Outcomes for A15

1

Explain cybersecurity risk in business terms using assets, threats, impact, likelihood, uncertainty, controls, and ownership.

2

Build and maintain a structured cyber risk register with decision states, treatment, evidence, owners, and review triggers.

3

Evaluate security controls using design intent, implementation state, operating evidence, control gaps, and remediation.

4

Connect security work to compliance frameworks, audits, policy mappings, exceptions, and evidence without confusing compliance with complete security.

5

Assess third-party and supplier risk using dependency, data access, criticality, sponsorship, evidence, concentration, and exit considerations.

6

Communicate risk to leaders through concise recommendations that explain impact, uncertainty, treatment options, residual risk, ownership, and next actions.

Professional Roles

Who Uses These Skills?

Security Risk Analyst

Frames risk scenarios, evaluates evidence, maintains risk registers, and supports treatment decisions.

Security Architect

Explains technical control design, dependencies, trust boundaries, and remediation options.

Governance / Compliance Analyst

Maps controls to policy and framework requirements, evidence, audits, and exceptions.

Control Owner

Operates the security control, maintains evidence, and remediates control weaknesses.

Risk Owner

Makes the business decision about residual risk and whether treatment or acceptance is appropriate.

Third-Party Risk Analyst

Evaluates supplier dependencies, evidence, sponsorship, contracts, concentration, and exit considerations.

Internal Auditor

Assesses whether evidence supports the stated control objective and whether governance processes are functioning.

Executive / Business Leader

Uses concise risk information to prioritize resources, deadlines, treatment options, and accepted residual risk.

Lesson Map

Ten Advanced Lessons

Each lesson adds one professional artifact. By A15.10, those artifacts combine into a complete Risk Register and Leadership Recommendation.

A15.1Portfolio Artifact

Risk Management in Cybersecurity

Focus

Understand cybersecurity risk as a business decision involving uncertainty, assets, threats, impact, ownership, controls, and acceptable residual risk.

Defensive Lab

Build a fictional Cyber Risk Context Map connecting business services, security concerns, owners, and decision boundaries.

Adds to portfolio

Cyber Risk Context Map

Open A15.1
A15.2Portfolio Artifact

Assets, Threats, Impact, and Likelihood

Focus

Evaluate risk using assets, threat events, business impact, likelihood, uncertainty, dependencies, and evidence without pretending risk scores are perfect predictions.

Defensive Lab

Create a fictional Risk Analysis Worksheet for business services with evidence-backed impact and likelihood reasoning.

Adds to portfolio

Risk Analysis Worksheet

Open A15.2
A15.3Portfolio Artifact

Risk Registers and Ownership

Focus

Turn scattered security concerns into a structured risk register with owners, status, evidence, treatment, due dates, and review triggers.

Defensive Lab

Build a fictional Cybersecurity Risk Register with accountable risk and control owners.

Adds to portfolio

Cybersecurity Risk Register

Open A15.3
A15.4Portfolio Artifact

Security Controls and Control Testing

Focus

Connect risks to preventive, detective, corrective, recovery, administrative, technical, and physical controls, then evaluate whether those controls are designed and operating as intended.

Defensive Lab

Create a fictional Control Effectiveness Review using safe evidence, expected outcomes, owners, and remediation.

Adds to portfolio

Control Effectiveness Review

Open A15.4
A15.5Portfolio Artifact

Compliance Framework Concepts

Focus

Understand frameworks, standards, control catalogs, policy mappings, and compliance evidence without treating compliance as identical to security.

Defensive Lab

Map fictional security requirements to a Framework and Control Mapping Register.

Adds to portfolio

Framework and Control Mapping Register

Open A15.5
A15.6Portfolio Artifact

Audit Evidence and Documentation

Focus

Evaluate evidence quality, freshness, attribution, completeness, repeatability, and traceability for audits and internal reviews.

Defensive Lab

Build a fictional Audit Evidence Register with strong, weak, stale, missing, and contradictory evidence examples.

Adds to portfolio

Audit Evidence Register

Open A15.6
A15.7Portfolio Artifact

Risk Acceptance and Exceptions

Focus

Distinguish remediation, mitigation, transfer, avoidance, acceptance, exceptions, compensating controls, residual risk, expiry, and risk-owner accountability.

Defensive Lab

Create a fictional Risk Acceptance and Exception Register with bounded approval and closure criteria.

Adds to portfolio

Risk Acceptance and Exception Register

Open A15.7
A15.8Portfolio Artifact

Third-Party Risk Concepts

Focus

Review supplier, vendor, partner, and service-provider dependencies using data access, criticality, contractual expectations, evidence, concentration risk, and exit planning.

Defensive Lab

Build a fictional Third-Party Risk Review covering suppliers, sponsors, evidence, dependencies, and treatment decisions.

Adds to portfolio

Third-Party Risk Review

Open A15.8
A15.9Portfolio Artifact

Communicating Risk to Leaders

Focus

Translate technical findings into decision-ready language using business impact, uncertainty, options, tradeoffs, timelines, ownership, and recommended action.

Defensive Lab

Create a fictional Leadership Risk Brief that turns a detailed risk register into a concise executive recommendation.

Adds to portfolio

Leadership Risk Brief

Open A15.9
A15.10Portfolio Artifact

Risk Decision Lab

Focus

Integrate assets, threat events, impact, likelihood, controls, evidence, exceptions, third parties, ownership, and leadership communication into one enterprise risk decision.

Defensive Lab

Produce the final Risk Register and Leadership Recommendation for a fictional organization.

Adds to portfolio

Risk Register and Leadership Recommendation

Open A15.10

Fictional Evidence Preview

Northbridge Risk Review Snapshot

RSK-01Decision: Monitor

Student Services Portal

Risk scenario

Sensitive student-support service depends on current identity, application, and database controls.

Impact

High

Likelihood

Medium

Existing controls

Strong authentication, workload authorization, database encryption, monitoring, recovery

Evidence

Current control review + current recovery evidence

Risk owner

Student Services Product Owner

RSK-02Decision: Treat

Legacy Reporting Service

Risk scenario

Legacy application uses broad trust relationships and has incomplete modernization.

Impact

High

Likelihood

Medium-High

Existing controls

Restricted network scope, modernization exception, partial monitoring

Evidence

Current exception + partial legacy inventory

Risk owner

Reporting Product Owner

RSK-03Decision: Treat / Monitor

Partner Scheduling Integration

Risk scenario

External partner certificate lifecycle is approaching renewal and service depends on timely transition.

Impact

Medium-High

Likelihood

Medium

Existing controls

Partner sponsor, certificate monitoring, renewal workflow

Evidence

Current certificate + renewal ticket

Risk owner

Integration Owner

RSK-04Decision: Monitor / Treat if overdue

Recovery Backup Repository

Risk scenario

Backup encryption is current but recovery evidence becomes stale if full restore testing is missed.

Impact

High

Likelihood

Low-Medium

Existing controls

Encrypted backup storage, protected replication, restore testing

Evidence

Current key inventory + restore-test status

Risk owner

Resilience Team

RSK-05Decision: Mitigate

Critical SaaS Provider

Risk scenario

A major business workflow depends heavily on one external provider.

Impact

High

Likelihood

Medium

Existing controls

Contract review, security evidence, continuity planning, exit strategy

Evidence

Supplier assessment + continuity plan

Risk owner

Business Service Owner

RSK-06Decision: Monitor

Analytics Export Workflow

Risk scenario

Sensitive data exports require both technical protection and business approval.

Impact

High

Likelihood

Low-Medium

Existing controls

Export authorization, encrypted staging, protected transfer, signed manifest

Evidence

Current export control evidence

Risk owner

Analytics Product Owner

Decision Language

Risk States Should Lead to Action

Monitor

Current risk and controls are acceptable, but evidence or business conditions require routine observation.

Treat

Risk should be reduced through a defined remediation or mitigation plan.

Conditional

The business decision can continue only under specific time-bounded conditions.

Accepted Risk

An authorized risk owner formally accepts the residual risk for a defined scope and period.

Blocked

The risk or control weakness is too significant for approval under current evidence.

Closed

Remediation and validation evidence show the risk was resolved or reduced to the approved target state.

Portfolio Outcome

Risk Register and Leadership Recommendation

A15 culminates in a professional-style risk package that shows not only what the risks are, but why they matter, what evidence supports them, which controls reduce them, who owns the decisions, what exceptions exist, which third parties matter, and what leaders should do next.

Executive Summary

Business context, top risks, overall risk posture, top treatment priorities, Accepted Risks, and leadership recommendation.

Risk Register

Risk IDs, services, scenarios, impact, likelihood, evidence, owners, controls, treatment, residual risk, status, and review triggers.

Control Effectiveness

Control objectives, design state, operating state, evidence quality, gaps, remediation, and owners.

Compliance and Audit Mapping

Policy/standard mappings, framework relationships, evidence ownership, freshness, exceptions, and audit notes.

Exception and Accepted Risk Register

Scope, reason, compensating controls, risk owner, expiry, residual risk, review cadence, and closure criteria.

Third-Party Risk Review

Supplier criticality, data access, dependencies, evidence, sponsor, contractual expectations, concentration, continuity, and exit planning.

Leadership Recommendation

Decision-ready summary of what should be treated now, what can be monitored, what can be accepted, and what must block approval.

Module Test

A15 Risk Management and Compliance Test

After all ten lessons, complete a 25-question assessment covering risk vocabulary, assets, threats, impact, likelihood, risk registers, control testing, compliance concepts, audit evidence, exceptions, third-party risk, leadership communication, and final risk decisions.

Open A15 Module Test

Module Navigation

Continue the Advanced Track