High School AdvancedA15.3Risk Management and Compliance
Lesson A15.3
Risk Registers and Ownership
A strong risk register is not a list of scary findings. It is a structured decision system that shows what the risk is, why it matters, who owns the decision, what controls exist, what treatment is planned, what evidence supports the status, and what would make the decision change.
This lesson uses fictional risk records and safe evidence only. It does not require scanning, exploiting, or investigating real systems, organizations, or suppliers.
High School Advanced • A15: Risk Management and Compliance • Lesson 3 of 10
30% complete
Readiness Check
A15.3 Entry Readiness
0/4 ready
Professional Hook
A Risk Exists in the Register Because Someone Needs to Make or Track a Decision
A useful register helps a leader answer practical questions: What could happen? How serious is it? What already reduces the risk? What remains? Who owns the decision? What treatment is underway? When will we review it again? What would allow us to close it?
A professional risk register turns analysis into ownership, treatment, evidence, review, and closure.
Learning Objectives
Five Capabilities for This Lesson
1
Explain how a cybersecurity risk register turns individual findings into a structured decision record with ownership, treatment, evidence, review, escalation, and closure.
2
Distinguish risk owner, control owner, remediation owner, system owner, data owner, evidence owner, and approver responsibilities.
3
Build risk records with scenario, impact, likelihood, controls, evidence, residual risk, treatment, status, due dates, review cadence, and change triggers.
4
Evaluate when a risk should remain Monitor, Treat, Conditional, Accepted Risk, Blocked, or Closed based on current evidence and governance.
5
Build a Cybersecurity Risk Register that becomes the third artifact in the A15 Risk Register and Leadership Recommendation.
Purpose
Why Organizations Maintain Risk Registers
One source of decision context
The register connects the scenario, business consequence, controls, evidence, ownership, treatment, and review state in one place.
Value: A reviewer can understand why the risk exists and what decision is being tracked without searching through scattered notes.
Visible accountability
The register names who owns the business risk, who operates controls, and who performs remediation.
Value: The organization can separate decision authority from technical execution.
Treatment tracking
The record shows actions, milestones, due dates, dependencies, and expected closure evidence.
Value: Risk treatment becomes a managed process rather than a one-time conversation.
Evidence and uncertainty history
The register preserves what evidence supported the decision and what remained partial, stale, missing, or contradictory.
Value: Future reviewers can tell why a previous decision was reasonable and when it should be reconsidered.
Prioritization
Impact, likelihood, criticality, control strength, evidence quality, and time sensitivity help compare risks.
Value: Limited security and business resources can focus on the most consequential unresolved risks.
Governance history
The register records decisions, approvals, exceptions, Accepted Risk, escalation, and closure.
Value: The organization can reconstruct who decided what, when, and on the basis of which evidence.
Core Fields
A Risk Record Should Be Specific Enough to Govern
Risk ID
Provide a stable reference that survives edits, owner changes, and treatment updates.
Strong: RSK-102
Weak: The old server issue
Business service / asset
Show what capability, data, identity, supplier, or technology is affected.
Strong: Legacy Reporting Service / historical sensitive reports
Weak: Server
Risk scenario
Explain what could happen and why it matters to the organization.
Strong: Legacy trust and transport gaps could expose sensitive reports or interrupt reporting services.
Weak: Legacy risk
Impact
Describe the business consequence if the scenario occurs.
Strong: High — sensitive data exposure, disruption, difficult investigation, governance impact
Weak: Bad
Likelihood
Record how plausible the scenario is under current conditions and evidence.
Strong: Medium-High — several active control gaps and incomplete ownership remain
Weak: Probably high
Current controls
Show which safeguards already reduce the scenario.
RSK-102 remains High residual risk because legacy trust, ownership, and transport gaps are still open. The record has an assigned business risk owner and active treatment, but closure criteria are not yet met.
Defensive recommendation: Keep the risk in Treat, track P0 milestones monthly, and escalate missed milestones to the risk owner and leadership.
Risk Aging and Escalation
An Old Open Risk Is Not Automatically a Bad Risk—But It Needs Explanation
Some risks remain open for years because the underlying business service continues to exist. The important question is whether the risk remains governed. A well-controlled critical service may stay in Monitor indefinitely. A high-risk legacy problem that repeatedly misses treatment milestones should escalate.
Healthy long-lived risk
Current owner, current controls, current evidence, acceptable residual risk, regular review, clear triggers.
Unhealthy aging risk
Overdue treatment, stale evidence, unclear owner, repeated exceptions, no escalation, or no closure plan.
A temporary workspace risk is encrypted and access-controlled, but current cleanup evidence is incomplete.
Safe Fictional Lab
Build a Cybersecurity Risk Register
Use fictional services, risks, owners, controls, treatment plans, evidence, and governance decisions only. The goal is to create a professional register that supports decisions without interacting with real systems.
1
Create at least twenty-five fictional risk records.
2
Give every risk a stable RSK ID.
3
Record the business service or asset.
4
Write a clear risk scenario.
5
Record impact and impact rationale.
6
Record likelihood and likelihood rationale.
7
Record current controls.
8
Record evidence sources and freshness.
9
Assign a business risk owner.
10
Assign control owners separately.
11
Assign remediation owner where treatment exists.
12
Assign evidence owner where useful.
13
Record treatment strategy.
14
Record current residual risk.
15
Record current status.
16
Record treatment milestone or due date.
17
Record review cadence.
18
Record event-driven review triggers.
19
Record assumptions and uncertainty.
20
Record escalation criteria.
21
Record closure criteria.
22
Record closure evidence when applicable.
23
Include at least five Monitor risks.
24
Include at least five Treat risks.
25
Include at least three Conditional risks.
26
Include at least two Accepted Risk records.
27
Include at least two Blocked risks.
28
Include at least two Closed risks with objective closure evidence.
29
Include at least three supplier or concentration risks.
30
Include at least three legacy or long-lived risks.
31
Include at least two risks with stale or contradictory evidence.
Lab boundary
Do not scan, probe, exploit, test, or investigate real systems, vendors, users, or accounts. Do not collect private risk records or confidential organizational documents. Use fictional and synthetic evidence only.
Analyze the Evidence
Evidence Analysis: Temporary Workspace Risk
Workspace storage is encrypted.
Project access is scoped.
Automated cleanup exists.
Current cleanup evidence is incomplete.
The risk owner and control owners are current.
What is the strongest status for RSK-107?
Advanced Challenge
Design a Risk Register Governance Standard
Create a fictional organization-wide standard that explains what every risk record must contain, who may change each field, how status transitions work, when escalation is required, and what evidence is necessary for closure.
1
Required risk fields
2
Risk-owner authority
3
Control-owner responsibility
4
Remediation-owner responsibility
5
Evidence-owner responsibility
6
Status transition rules
7
Accepted Risk requirements
8
Blocked-state requirements
9
Review cadence
10
Review triggers
11
Due-date standards
12
Escalation thresholds
13
Overdue-risk handling
14
Closure criteria
15
Closure evidence
16
Leadership reporting
The strongest governance standard should make risk status changes explainable and evidence-based rather than dependent on informal judgment.
Defender Habits
A15.3 Defender Checklist
Skill Check
Seven Questions
Check Your Understanding
A15.3 Mini Quiz: Risk Registers and Ownership
Choose your answers first. Explanations appear only after submission.
1. What is the main purpose of a cybersecurity risk register?
2. Who should normally own the business decision about residual risk?
3. When should a risk normally be Closed?
4. What is strongest for an Accepted Risk record?
5. Why should control ownership be separate from risk ownership?
6. What should happen when supporting evidence for a Monitor risk becomes stale?
7. What is a review trigger?
Portfolio Prompt
Portfolio Build — Cybersecurity Risk Register
Create the third artifact for your A15 Risk Register and Leadership Recommendation: a fictional Cybersecurity Risk Register with at least twenty-five records. Include RSK ID, business service/asset, risk scenario, impact, likelihood, current controls, evidence, evidence freshness, risk owner, control owner, remediation owner, evidence owner where useful, treatment, residual risk, status, due date/milestone, review cadence, review trigger, escalation criteria, closure criteria, closure evidence, uncertainty, and next action.
Use stable IDs.
Keep risk owner separate from control owner.
Use meaningful milestones rather than vague deadlines.
Keep Accepted Risk visible.
Close only with validation evidence.
Use fictional provider-neutral records only.
Confidence / Readiness Reflection
Are You Ready for A15.4?
A15.4 focuses on Security Controls and Control Testing. Before continuing, make sure every risk in your register can point to the controls that reduce it and the evidence that supports those controls.
1
I can explain why a risk register is a decision tool.
2
I can distinguish risk owner, control owner, and remediation owner.
3
I can choose a status that matches current evidence.
4
I can define meaningful closure criteria.
5
I can explain when an overdue or high-risk record should escalate.
Portfolio Build Guide
How to Make the Cybersecurity Risk Register Look Professional
Use stable IDs
A risk should keep the same identifier through treatment, owner change, escalation, acceptance, and closure.
Separate owner roles
Risk owner, control owner, remediation owner, and evidence owner may all be different.
Show decision state
Draft, Open, Treat, Conditional, Accepted Risk, Blocked, Monitor, and Closed should have clear meanings.
Use meaningful milestones
A due date should describe what should be different by that date.
Show evidence freshness
Risk status should lose confidence when evidence becomes stale or contradictory.
Use objective closure criteria
A risk closes because evidence shows the target state was reached—not because the task list is empty.
Show escalation rules
High residual risk, missed P0 work, missing ownership, or above-tolerance conditions should have a path to leadership.
Connect forward
A15.4 will evaluate whether the controls referenced in your risk register are actually designed and operating as intended.
Key Takeaways
What You Should Remember
1.A risk register turns analysis into an ongoing governance process.
2.Risk ownership, control ownership, remediation ownership, and evidence ownership are different responsibilities.
3.Status should reflect current residual risk and evidence, not project activity alone.
4.Accepted Risk should remain visible and reviewable.
5.Closure requires objective validation evidence.
6.Meaningful milestones are stronger than vague due dates.
7.Stale evidence should reduce confidence in the current decision.
8.High-impact, overdue, unowned, or above-tolerance risks need escalation.
9.Review triggers keep risk records current when business or technical conditions change.
10.The Cybersecurity Risk Register prepares you for A15.4 Security Controls and Control Testing.
Do not scan, probe, exploit, test, or investigate real systems, vendors, accounts, or people. Do not collect private risk records or confidential organizational evidence. All records, owners, systems, logs, and evidence in this lesson are fictional.
Lesson Complete
A15.3 Risk Registers and Ownership Complete
You now have a structured model for risk records, ownership, treatment, residual risk, milestones, escalation, evidence, and closure. Next, A15.4 focuses on Security Controls and Control Testing.