High School IntermediateModule I14Lesson 2 of 8

I14.2 Risk Identification and Assessment

Learn how defenders identify fictional assets, threats, vulnerabilities, exposure, controls, likelihood, impact, uncertainty, ownership, and review needs while creating transparent and evidence-based risk assessments.

Lesson Progress

Risk Identification and Assessment

High School IntermediateI14: Security Policies and Risk • Lesson 2 of 8

25% complete

Readiness Check

Before You Start

0/5 ready

Professional Hook

A High Risk Score Is Not Useful without a Clear Scenario

The fictional Northbridge risk register contains several high or medium-high ratings, but the strongest records explain exactly what could happen, which asset could be affected, which weakness enables the scenario, which controls reduce it, how likely it is, what impact could occur, how confident the evidence is, who owns the decision, and when the risk must be reassessed.

Weak assessment

Assign a dramatic score, copy an alert into the register, assume the worst impact, hide uncertainty, and leave the risk without a decision owner or review date.

Professional assessment

Define the scenario, validate evidence, assess controls, explain likelihood and impact, record confidence and limits, assign ownership, and schedule reassessment.

Objective 1

Explain how fictional security risk connects assets, threats, vulnerabilities, exposure, control conditions, dependencies, likelihood, impact, uncertainty, ownership, and review.

Objective 2

Distinguish fictional direct observations, assumptions, scenarios, evidence, indicators, control gaps, potential consequences, confirmed impact, confidence, and missing information.

Objective 3

Build a fictional risk register that documents scope, assets, threats, vulnerabilities, controls, likelihood, impact, evidence, assumptions, owners, treatment status, and review dates.

Objective 4

Evaluate fictional risk using transparent criteria instead of relying on dramatic language, one alert, one score, or unsupported certainty.

Objective 5

Create a portfolio-safe fictional risk-assessment package with an evidence register, scenario analysis, scoring rationale, findings, limitations, owners, and reassessment plan.

Why This Matters

Risk Decisions Guide Where Time, Money, Attention, and Authority Go

Fictional organizations cannot fix every weakness at once. Risk assessment helps them compare scenarios using business value, exposure, control health, likelihood, impact, uncertainty, and ownership. A weak assessment can waste resources, delay urgent action, exaggerate harmless conditions, or hide major dependencies. A strong assessment makes the reasoning visible so another reviewer can challenge, improve, and approve it.

Core Concept

Use the Asset–Scenario–Evidence–Decision Model

Asset

Which fictional service, data, identity, process, supplier, user outcome, reputation, or recovery capability has value?

Scenario

Which fictional threat, vulnerability, exposure, event path, control condition, and consequence form a plausible risk?

Evidence

Which fictional records support likelihood, impact, control effectiveness, assumptions, alternatives, confidence, and limitations?

Decision

Which fictional owner selects treatment, accepts residual risk, funds action, escalates delay, validates closure, and sets reassessment?

Key Vocabulary

Risk Identification, Evidence, and Decision Terms

Risk

A fictional possibility that a threat could affect an asset or business objective through one or more vulnerabilities or control gaps, creating consequences under uncertain conditions.

Asset

A fictional person, service, system, device, application, data set, process, facility, supplier relationship, reputation, or capability that has value.

Threat

A fictional circumstance, event, actor, failure, mistake, environmental condition, or dependency that could cause harm.

Vulnerability

A fictional weakness, missing safeguard, design flaw, process gap, configuration issue, ownership problem, or dependency that could be used or triggered.

Exposure

The fictional degree to which an asset, service, identity, data set, or process can be reached, affected, influenced, or disrupted.

Control

A fictional preventive, detective, corrective, recovery, deterrent, governance, physical, technical, or administrative safeguard.

Likelihood

A fictional judgment about how plausible a risk scenario is during a defined time period, based on evidence, exposure, controls, history, and uncertainty.

Impact

A fictional judgment about possible consequences to confidentiality, integrity, availability, safety, privacy, finance, operations, reputation, compliance, users, or recovery.

Inherent risk

A fictional estimate of risk before considering the effectiveness of current controls.

Residual risk

A fictional estimate of risk remaining after current or planned controls, exceptions, limitations, and dependencies are considered.

Risk scenario

A fictional structured statement connecting an asset, threat, vulnerability, event path, control condition, and potential consequence.

Risk register

A fictional record of identified risks, evidence, assumptions, likelihood, impact, confidence, owners, treatments, status, and review dates.

Evidence confidence

A fictional rating describing how strongly the supplied records support a risk conclusion.

Assumption

A fictional condition treated as true for analysis even though the supplied evidence does not fully verify it.

Uncertainty

The fictional amount of important information that is unknown, incomplete, delayed, outdated, disputed, or outside the evidence boundary.

Risk appetite

A fictional leadership statement describing the amount and type of risk the organization is generally willing to pursue or retain.

Risk Components

Eight Parts of a Defensible Fictional Risk Scenario

Asset and objective

Review question

What fictional service, data, identity, process, supplier, user outcome, reputation, or recovery capability must be protected?

Evidence

Asset register, service map, data classification, business owner, user dependency, recovery requirement, and criticality record.

Weak assessment

Risk is described without identifying the exact thing of value or the business objective that could be affected.

Threat condition

Review question

Which fictional actor, event, error, failure, environmental condition, dependency, or change could create harm?

Evidence

Incident history, threat reports, supplier notices, failure records, change history, owner interviews, and scenario evidence.

Weak assessment

The assessment uses vague labels such as cyberattack without describing a plausible event path.

Vulnerability or gap

Review question

Which fictional weakness, missing control, poor process, stale access, configuration issue, ownership gap, or dependency enables the scenario?

Evidence

Control tests, configuration review, policy gap, exception, access record, procedure failure, and validation results.

Weak assessment

The assessment treats the threat itself as the vulnerability or assumes a weakness without evidence.

Exposure and reachability

Review question

How broadly can the fictional condition reach, influence, interrupt, or affect the asset?

Evidence

Access paths, network reachability, user population, supplier connectivity, data flow, privilege scope, and process dependency.

Weak assessment

The assessment assumes technical capability equals practical exposure without reviewing all controls.

Existing controls

Review question

Which fictional preventive, detective, corrective, recovery, governance, or compensating controls reduce the scenario?

Evidence

Control design, owner, operating records, test results, metrics, alerts, incidents, exceptions, and remediation status.

Weak assessment

The assessment lists controls but does not evaluate whether they are current, healthy, complete, or effective.

Likelihood

Review question

How plausible is the fictional scenario in the defined time window after considering exposure, history, controls, dependencies, and uncertainty?

Evidence

Observed conditions, prior events, control failures, frequency, owner reports, test evidence, supplier status, and environmental change.

Weak assessment

The score is chosen from intuition without a transparent rationale or confidence statement.

Impact

Review question

Which fictional confidentiality, integrity, availability, privacy, safety, financial, operational, reputational, legal, or recovery consequences could occur?

Evidence

Business-impact analysis, data class, service criticality, recovery objectives, user dependency, contract, and leadership priorities.

Weak assessment

Potential impact is written as confirmed impact even though the event has not occurred.

Ownership and review

Review question

Who owns the fictional asset, risk decision, control operation, treatment, evidence, escalation, and next reassessment?

Evidence

Responsibility matrix, risk register, policy, treatment plan, approval, due date, review date, and closure record.

Weak assessment

A risk remains open without a decision owner, treatment owner, deadline, or reassessment trigger.

Evidence Quality

Eight Questions before Trusting a Fictional Risk Score

Source relevance

Strong evidence use

The fictional source directly addresses the asset, threat, control, time window, and decision being evaluated.

Weak evidence use

A general or unrelated source is used as if it proves the specific risk.

Reviewer question

Does this evidence answer the actual risk question?

Source health

Strong evidence use

The fictional source is current, complete enough, accessible, properly scoped, and owned.

Weak evidence use

The source is stale, delayed, partial, unowned, or missing important coverage.

Reviewer question

Can the source be trusted within the stated boundary?

Independence

Strong evidence use

Several fictional sources with different origins support the same conclusion.

Weak evidence use

Multiple dashboards, alerts, screenshots, and exports all come from one parent source.

Reviewer question

Are these truly separate sources or repeated views of the same evidence?

Timeliness

Strong evidence use

The fictional evidence matches the current decision window and preserves event, receipt, review, and approval dates.

Weak evidence use

Old evidence is used without checking whether the environment or control changed.

Reviewer question

Is the evidence current enough for this decision?

Completeness

Strong evidence use

The fictional evidence covers the relevant assets, users, systems, suppliers, regions, controls, and exceptions.

Weak evidence use

Important exclusions, blind spots, dependencies, or populations are omitted.

Reviewer question

What important part of the scenario is outside the evidence?

Consistency

Strong evidence use

Fictional sources agree or differences are explained through timing, scope, ownership, or method.

Weak evidence use

Conflicting evidence is ignored or one preferred source is accepted without analysis.

Reviewer question

Do the sources tell the same story, and if not, why?

Traceability

Strong evidence use

Every fictional finding links to exact records, owners, dates, assumptions, calculations, and review notes.

Weak evidence use

The score appears with no explanation of how it was reached.

Reviewer question

Can another reviewer reconstruct the conclusion?

Limitations

Strong evidence use

Fictional missing data, uncertainty, bias, coverage gaps, assumptions, and alternate explanations are documented.

Weak evidence use

The assessment sounds certain despite incomplete evidence.

Reviewer question

What can this evidence not prove?

Risk Register Design

Eight Fields for Transparent Fictional Risk Assessment

Risk statement

Purpose

Connects a fictional asset, threat, vulnerability, event path, and consequence in one clear scenario.

Fictional example

Because a supplier account remains active after project closure, the supplier could retain access to confidential support records, causing unauthorized access or delayed detection.

Quality standard

The statement describes a plausible possibility without claiming the event already happened.

Inherent likelihood

Purpose

Estimates fictional scenario plausibility before current controls are considered.

Fictional example

Medium-High because the account exists, the project ended, and the supplier previously required broad access.

Quality standard

The rationale uses evidence and a defined time window.

Inherent impact

Purpose

Estimates fictional maximum plausible consequence before current controls are considered.

Fictional example

High because the account could reach confidential support records and affect privacy, trust, and operations.

Quality standard

Potential impact remains separate from confirmed harm.

Control effectiveness

Purpose

Evaluates how strongly fictional preventive, detective, corrective, recovery, and governance controls reduce the scenario.

Fictional example

Network restriction is healthy, but sponsor review and account expiration controls failed.

Quality standard

Control design and actual operation are evaluated separately.

Residual likelihood

Purpose

Estimates fictional plausibility after current controls and weaknesses are considered.

Fictional example

Medium because network restriction reduces reach, but the active account and expired exception remain.

Quality standard

The score reflects both controls and their limitations.

Residual impact

Purpose

Estimates fictional consequence after current controls, recovery, detection, and response capabilities are considered.

Fictional example

Medium-High because access scope is limited but confidential data and delayed detection remain possible.

Quality standard

Recovery and detection reduce consequence only when evidence supports their effectiveness.

Confidence and uncertainty

Purpose

Shows how strongly fictional evidence supports the likelihood and impact judgments.

Fictional example

Medium confidence because account status and scope are known but post-expiration activity logs are incomplete.

Quality standard

Uncertainty changes the wording and review priority rather than being hidden.

Owner and review trigger

Purpose

Assigns fictional decision authority, treatment ownership, due date, reassessment date, and event-based triggers.

Fictional example

Third-Party Risk Owner reviews in seven fictional days or immediately if supplier activity appears.

Quality standard

The risk cannot remain open without an accountable decision and next review.

Risk Register

Northbridge Fictional Risk Records

NBR-RISK-01

Confidential support records

L: MediumI: HighMedium-High

A fictional supplier account remains active after the related project and exception ended.

Evidence

Account status, expired exception, completed project, sponsor record, access scope, and incomplete post-expiration activity logs.

Risk owner

Third-Party Risk Owner

Evidence limit

No unauthorized sign-in, record access, or disclosure is confirmed.

NBR-RISK-02

Critical reporting service

L: MediumI: HighMedium

A fictional service could experience delayed recovery because no business recovery risk owner is confirmed.

Evidence

Criticality record, recovery procedure, operator roster, missing risk owner, recovery objective, and escalation map.

Risk owner

Business Service Executive

Evidence limit

The service may still recover successfully with the existing technical team.

NBR-RISK-03

Organization-wide access governance

L: MediumI: Medium-HighMedium

A fictional business unit may retain inappropriate access because its quarterly review is incomplete.

Evidence

Access-review schedule, completed units, incomplete unit, role inventory, owner reminder, and review procedure.

Risk owner

Identity Governance

Evidence limit

No specific inappropriate account or action is confirmed.

NBR-RISK-04

Leadership decision quality

L: Medium-HighI: MediumHigh

Fictional leaders could make poor security decisions because the ninety-eight percent compliance metric excludes undocumented systems.

Evidence

Dashboard, metric definition, asset inventory, excluded-system uncertainty, control records, and owner response.

Risk owner

Security Metrics Owner

Evidence limit

The measured systems may still have strong control performance.

NBR-RISK-05

Supplier offboarding process

L: Medium-HighI: HighMedium-High

Fictional stale supplier access could recur because an incident improvement action has no assigned policy or procedure owner.

Evidence

Incident review, offboarding recommendation, action tracker, ownership matrix, supplier procedure, and current gap.

Risk owner

Governance Improvement Lead

Evidence limit

Some operational improvement may exist outside the supplied governance records.

NBR-RISK-06

Encryption exception process

L: MediumI: HighMedium

Fictional encryption exceptions could be approved inconsistently because the standard does not name a validation owner.

Evidence

Encryption standard, exception template, control-owner map, approval path, and review records.

Risk owner

Security Architecture

Evidence limit

No weak encryption or exposed data is confirmed.

NBR-RISK-07

Residual-risk decisions

L: MediumI: Medium-HighHigh

A fictional accepted risk could remain unmanaged because its six-month review date passed without renewal or closure evidence.

Evidence

Risk decision, approval, expiration, treatment status, owner record, and missing reassessment.

Risk owner

Executive Risk Owner

Evidence limit

The underlying risk may have changed since the last decision.

NBR-RISK-08

Information security policy framework

L: MediumI: MediumMedium-High

Fictional control requirements could become misaligned because the main policy review is overdue while services and suppliers changed.

Evidence

Policy review date, current service inventory, supplier changes, new dependencies, control map, and governance calendar.

Risk owner

Security Policy Owner

Evidence limit

The policy may remain substantively accurate despite the overdue review.

Defensive Workflow

Complete a Fictional Risk Identification and Assessment

1

Define the fictional risk question

State the asset, business objective, scope, time window, authority, owners, evidence, privacy limits, scoring method, and prohibited real-world use.

Output: Risk-assessment charter.

2

Identify assets and dependencies

Map fictional services, data, users, identities, suppliers, processes, facilities, technologies, recovery needs, and dependency chains.

Output: Asset and dependency register.

3

Build risk scenarios

Connect fictional threats, vulnerabilities, exposure, event paths, control conditions, and potential consequences.

Output: Structured risk-scenario library.

4

Validate evidence quality

Review fictional relevance, health, independence, timeliness, completeness, consistency, traceability, assumptions, and limitations.

Output: Evidence-quality register.

5

Evaluate likelihood and impact

Score fictional inherent and residual risk using transparent criteria, current controls, business context, uncertainty, and confidence.

Output: Risk scoring rationale.

6

Prioritize and compare

Compare fictional risk level, criticality, control weakness, uncertainty, dependency, decision deadline, and remediation readiness.

Output: Risk-ranked register.

7

Assign owners and next actions

Document fictional risk owner, treatment owner, evidence owner, due date, escalation, review trigger, and required decision.

Output: Owned risk action plan.

8

Review and communicate

Confirm fictional findings, alternatives, confidence, limitations, leadership meaning, residual risk, reassessment, and portfolio safety.

Output: Reviewed risk-assessment package.

Fake Dashboard

Fake Northbridge Risk Assessment Dashboard

Training dashboard for fictional risk evidence only.

Risk records reviewed

8

Supplier, recovery, identity, metrics, offboarding, encryption, residual-risk, and policy scenarios are mapped.

High-impact scenarios

4

Supplier access, recovery ownership, offboarding recurrence, and encryption exceptions require prioritized review.

Confirmed incidents

0

The supplied fictional evidence supports risk scenarios and control gaps but no confirmed incident or disclosure.

Fake SOC Alert

Expired Supplier Exception with Active Account

Source: Fake Risk Assessment Console • Time: 10:15 AM

High Severity
A fictional supplier account remains active after the related project and access exception ended. The account can reach a limited support service, but post-expiration activity evidence is incomplete.
Defensive recommendation: Document the asset, scenario, controls, exposure, likelihood, impact, confidence, and limitations. Confirm the sponsor and current need, review activity, remove or renew access through authorized governance, validate the outcome, monitor, assign a risk owner, and avoid claiming unauthorized use without evidence.

Fake Log Panel

Fake Northbridge Risk Assessment Records

training-log-viewer.log
09:00 CHARTER scope='risk identification and assessment'
09:08 ASSET support-records classification='confidential'
09:15 THREAT stale-supplier-access scenario='plausible'
09:22 VULNERABILITY exception='expired' account='active'
09:29 CONTROL network-scope='limited' sponsor-review='failed'
09:36 EVIDENCE activity-logs='incomplete'
09:43 LIKELIHOOD residual='Medium'
09:50 IMPACT potential='High' confirmed='none'
09:57 CONFIDENCE='Medium-High'
10:04 OWNER third-party-risk='assigned'
10:12 REVIEW trigger='7 days or supplier activity'
10:20 RISK recovery-owner-gap='Medium x High'
10:28 RISK metric-denominator='Medium-High x Medium'
10:36 RISK offboarding-recurrence='Medium-High x High'
10:44 FINDING confirmed_incident='not supported'
10:52 PRIORITY stale-access_and_owner-gaps='first'

Training note: this is fake data for defensive analysis practice only.

Findings Matrix

Northbridge Risk Findings and Limits

NBR-RISK-F01Medium-High

The fictional expired supplier exception creates a high-impact residual-risk scenario because the account remains active, but the supplied evidence does not confirm post-expiration use.

Evidence support

Exception expiration, account status, project closure, sponsor record, access scope, network restriction, and incomplete activity evidence.

Alternative

The supplier may still have an approved business need that was not documented on time.

Limitation

No unauthorized sign-in, record access, or disclosure is confirmed.

NBR-RISK-F02Medium

The fictional critical reporting service has a material recovery-governance risk because technical operation is assigned but business recovery ownership is unclear.

Evidence support

Service criticality, recovery procedure, operator roster, recovery objective, missing risk owner, and escalation map.

Alternative

An informal business owner may exist outside the supplied records.

Limitation

The ownership gap does not prove recovery would fail.

NBR-RISK-F03High

The fictional ninety-eight percent compliance metric creates a decision-quality risk because the denominator and excluded systems are not defined.

Evidence support

Dashboard, metric definition, asset inventory, excluded-system uncertainty, control records, and metric-owner response.

Alternative

The percentage may be accurate within a narrower undocumented scope.

Limitation

The finding does not prove poor control operation in the measured systems.

NBR-RISK-F04Medium-High

The fictional supplier-offboarding risk is likely to recur unless the incident lesson is assigned to policy, procedure, control, and review owners.

Evidence support

Incident recommendation, action tracker, missing owner, supplier access exception, procedure gap, and governance matrix.

Alternative

Operational teams may have changed practice without updating governance evidence.

Limitation

Current supplier offboarding performance is only partially evidenced.

NBR-RISK-F05High

The fictional risk register should separate score confidence from risk level because several high-impact scenarios rely on incomplete activity or ownership evidence.

Evidence support

Supplier activity gap, informal-owner possibility, incomplete access review, metric exclusions, and stale decision records.

Alternative

Additional records may raise or lower both likelihood and confidence.

Limitation

Confidence does not directly replace likelihood or impact.

NBR-RISK-F06High

The safest immediate sequence is to resolve active stale access and missing decision ownership before revising lower-priority documentation and metrics.

Evidence support

Active supplier account, critical-service owner gap, stale risk acceptance, overdue access review, policy review, and metric ambiguity.

Alternative

Leadership may reorder actions based on current business deadlines or incident conditions.

Limitation

Final priority requires fictional risk-owner approval.

Analyze the Evidence

What Does the Active Supplier Account Support?

The fictional supplier project ended.
The access exception expired.
The supplier account remains active.
The account can reach only a limited support service.
Post-expiration activity evidence is incomplete.
No unauthorized sign-in, record access, or disclosure is shown.
An authorized owner can remove or formally renew the access.

Which conclusion is strongest?

Common Mistakes

Mistakes That Weaken Risk Identification and Assessment

Treating fictional risk as a dramatic event description instead of a structured connection among asset, threat, vulnerability, exposure, controls, likelihood, and impact.
Using the words threat, vulnerability, exposure, and risk as if they mean the same thing.
Scoring likelihood or impact without stating the time window, criteria, evidence, assumptions, and confidence.
Treating a high potential impact as proof that the impact already occurred.
Treating an active account, broad permission, overdue review, or missing owner as proof of malicious activity.
Listing controls without checking whether they are designed well, operating, monitored, current, complete, and owned.
Using several screenshots or dashboards from one parent system as independent evidence.
Ignoring supplier, process, people, recovery, governance, and ownership dependencies because the assessment focuses only on technology.
Treating uncertainty as a reason to avoid a decision instead of documenting assumptions, confidence, limits, and review triggers.
Using a numeric score without a written scenario and rationale.
Allowing a technical analyst to accept residual business risk without documented authority.
Leaving risks open without a risk owner, treatment owner, due date, escalation, review date, or event-based trigger.
Closing a fictional risk because a ticket is complete without validating the control, residual risk, evidence, and owner approval.
Using or exposing any real private risk register, company architecture, employee identity, supplier contract, school record, credential, incident evidence, or confidential business information.

Safe Practice Lab

Build the Northbridge Risk Identification and Assessment Package

Your fictional assignment

Assets, Scenarios, Evidence, Scoring, Ownership, and Review

Use only the supplied fictional Northbridge records to complete an end-to-end risk identification and assessment.

Required deliverables

  1. Risk-assessment charter with scope, owners, evidence, time window, method, privacy, and deliverables.
  2. Asset, service, data, supplier, user, recovery, and dependency register.
  3. Structured risk scenarios with threats, vulnerabilities, exposure, controls, and consequences.
  4. Evidence-quality review with assumptions, alternatives, confidence, and limitations.
  5. Inherent and residual likelihood and impact rationale.
  6. Risk-ranked register with owners, due dates, treatment status, and review triggers.
  7. Findings with evidence, alternatives, confidence, limitations, and decision needs.
  8. Technical summary, leadership summary, reflection, and portfolio-safety statement.
Complete the lab only with fictional evidence displayed on this page. Do not use real company, employee, supplier, contract, credential, school, incident, or confidential risk information.

Scenario Decision Lab

The Risk Score Is High, but Activity Evidence Is Incomplete

The fictional supplier account remains active after the exception expired, but the supplied logs do not cover the full post-expiration period.

Scenario Decision Lab

A Critical Service Has a Recovery Procedure but No Risk Owner

The fictional reporting service has technical operators and a tested procedure, but no authorized business owner for recovery risk decisions.

Defender Habits

Risk Identification and Assessment Checklist

Check Your Understanding

I14.2 Mini Quiz: Risk Identification and Assessment

Choose your answers first. Explanations appear only after submission.

1. What makes a fictional risk scenario complete?

2. What is the difference between fictional inherent and residual risk?

3. Which conclusion about an active fictional supplier account is strongest?

4. Why should fictional evidence confidence be recorded separately from risk level?

5. What makes fictional likelihood scoring defensible?

6. Who should normally own a fictional residual-risk decision?

7. What makes a fictional risk finding defensible?

Portfolio Prompt

Portfolio Prompt

Create a fictional Risk Identification and Assessment Package for Northbridge. Include the assessment charter, asset and dependency register, risk scenarios, evidence-quality register, assumptions, likelihood and impact criteria, inherent and residual risk, control-effectiveness review, confidence and limitations, risk register, priority rationale, owner and treatment map, reassessment triggers, technical summary, leadership summary, reflection, and a portfolio-safety statement.

Use only fictional assets, services, identities, suppliers, risks, evidence, owners, dates, scores, and decisions.
Do not treat a high score, active account, overdue review, missing owner, or weak control as proof of an incident or confirmed impact.
Make every score traceable to a scenario, evidence, controls, assumptions, time window, and confidence level.
Show where technical analysis ends and authorized business risk ownership begins.

Key Takeaways

What You Should Remember

1.Risk assessment connects assets, threats, vulnerabilities, exposure, controls, likelihood, impact, uncertainty, ownership, and review.
2.A strong risk record explains the scenario and rationale instead of presenting only a score.
3.Potential impact is not the same as confirmed impact.
4.Inherent risk is assessed before current controls, while residual risk considers control effectiveness and limitations.
5.Evidence confidence should be recorded separately from risk level.
6.Residual-risk decisions require authorized business ownership and scheduled reassessment.
7.Portfolio artifacts should use fully fictional risk evidence and never expose real organizational records.

Navigation

Continue Module I14