Risk
A fictional possibility that a threat could affect an asset or business objective through one or more vulnerabilities or control gaps, creating consequences under uncertain conditions.
Learn how defenders identify fictional assets, threats, vulnerabilities, exposure, controls, likelihood, impact, uncertainty, ownership, and review needs while creating transparent and evidence-based risk assessments.
Lesson Progress
High School Intermediate • I14: Security Policies and Risk • Lesson 2 of 8
Readiness Check
0/5 ready
Professional Hook
The fictional Northbridge risk register contains several high or medium-high ratings, but the strongest records explain exactly what could happen, which asset could be affected, which weakness enables the scenario, which controls reduce it, how likely it is, what impact could occur, how confident the evidence is, who owns the decision, and when the risk must be reassessed.
Weak assessment
Assign a dramatic score, copy an alert into the register, assume the worst impact, hide uncertainty, and leave the risk without a decision owner or review date.
Professional assessment
Define the scenario, validate evidence, assess controls, explain likelihood and impact, record confidence and limits, assign ownership, and schedule reassessment.
Objective 1
Explain how fictional security risk connects assets, threats, vulnerabilities, exposure, control conditions, dependencies, likelihood, impact, uncertainty, ownership, and review.
Objective 2
Distinguish fictional direct observations, assumptions, scenarios, evidence, indicators, control gaps, potential consequences, confirmed impact, confidence, and missing information.
Objective 3
Build a fictional risk register that documents scope, assets, threats, vulnerabilities, controls, likelihood, impact, evidence, assumptions, owners, treatment status, and review dates.
Objective 4
Evaluate fictional risk using transparent criteria instead of relying on dramatic language, one alert, one score, or unsupported certainty.
Objective 5
Create a portfolio-safe fictional risk-assessment package with an evidence register, scenario analysis, scoring rationale, findings, limitations, owners, and reassessment plan.
Why This Matters
Fictional organizations cannot fix every weakness at once. Risk assessment helps them compare scenarios using business value, exposure, control health, likelihood, impact, uncertainty, and ownership. A weak assessment can waste resources, delay urgent action, exaggerate harmless conditions, or hide major dependencies. A strong assessment makes the reasoning visible so another reviewer can challenge, improve, and approve it.
Core Concept
Asset
Which fictional service, data, identity, process, supplier, user outcome, reputation, or recovery capability has value?
Scenario
Which fictional threat, vulnerability, exposure, event path, control condition, and consequence form a plausible risk?
Evidence
Which fictional records support likelihood, impact, control effectiveness, assumptions, alternatives, confidence, and limitations?
Decision
Which fictional owner selects treatment, accepts residual risk, funds action, escalates delay, validates closure, and sets reassessment?
Key Vocabulary
A fictional possibility that a threat could affect an asset or business objective through one or more vulnerabilities or control gaps, creating consequences under uncertain conditions.
A fictional person, service, system, device, application, data set, process, facility, supplier relationship, reputation, or capability that has value.
A fictional circumstance, event, actor, failure, mistake, environmental condition, or dependency that could cause harm.
A fictional weakness, missing safeguard, design flaw, process gap, configuration issue, ownership problem, or dependency that could be used or triggered.
The fictional degree to which an asset, service, identity, data set, or process can be reached, affected, influenced, or disrupted.
A fictional preventive, detective, corrective, recovery, deterrent, governance, physical, technical, or administrative safeguard.
A fictional judgment about how plausible a risk scenario is during a defined time period, based on evidence, exposure, controls, history, and uncertainty.
A fictional judgment about possible consequences to confidentiality, integrity, availability, safety, privacy, finance, operations, reputation, compliance, users, or recovery.
A fictional estimate of risk before considering the effectiveness of current controls.
A fictional estimate of risk remaining after current or planned controls, exceptions, limitations, and dependencies are considered.
A fictional structured statement connecting an asset, threat, vulnerability, event path, control condition, and potential consequence.
A fictional record of identified risks, evidence, assumptions, likelihood, impact, confidence, owners, treatments, status, and review dates.
A fictional rating describing how strongly the supplied records support a risk conclusion.
A fictional condition treated as true for analysis even though the supplied evidence does not fully verify it.
The fictional amount of important information that is unknown, incomplete, delayed, outdated, disputed, or outside the evidence boundary.
A fictional leadership statement describing the amount and type of risk the organization is generally willing to pursue or retain.
Risk Components
Review question
What fictional service, data, identity, process, supplier, user outcome, reputation, or recovery capability must be protected?
Evidence
Asset register, service map, data classification, business owner, user dependency, recovery requirement, and criticality record.
Weak assessment
Risk is described without identifying the exact thing of value or the business objective that could be affected.
Review question
Which fictional actor, event, error, failure, environmental condition, dependency, or change could create harm?
Evidence
Incident history, threat reports, supplier notices, failure records, change history, owner interviews, and scenario evidence.
Weak assessment
The assessment uses vague labels such as cyberattack without describing a plausible event path.
Review question
Which fictional weakness, missing control, poor process, stale access, configuration issue, ownership gap, or dependency enables the scenario?
Evidence
Control tests, configuration review, policy gap, exception, access record, procedure failure, and validation results.
Weak assessment
The assessment treats the threat itself as the vulnerability or assumes a weakness without evidence.
Review question
How broadly can the fictional condition reach, influence, interrupt, or affect the asset?
Evidence
Access paths, network reachability, user population, supplier connectivity, data flow, privilege scope, and process dependency.
Weak assessment
The assessment assumes technical capability equals practical exposure without reviewing all controls.
Review question
Which fictional preventive, detective, corrective, recovery, governance, or compensating controls reduce the scenario?
Evidence
Control design, owner, operating records, test results, metrics, alerts, incidents, exceptions, and remediation status.
Weak assessment
The assessment lists controls but does not evaluate whether they are current, healthy, complete, or effective.
Review question
How plausible is the fictional scenario in the defined time window after considering exposure, history, controls, dependencies, and uncertainty?
Evidence
Observed conditions, prior events, control failures, frequency, owner reports, test evidence, supplier status, and environmental change.
Weak assessment
The score is chosen from intuition without a transparent rationale or confidence statement.
Review question
Which fictional confidentiality, integrity, availability, privacy, safety, financial, operational, reputational, legal, or recovery consequences could occur?
Evidence
Business-impact analysis, data class, service criticality, recovery objectives, user dependency, contract, and leadership priorities.
Weak assessment
Potential impact is written as confirmed impact even though the event has not occurred.
Review question
Who owns the fictional asset, risk decision, control operation, treatment, evidence, escalation, and next reassessment?
Evidence
Responsibility matrix, risk register, policy, treatment plan, approval, due date, review date, and closure record.
Weak assessment
A risk remains open without a decision owner, treatment owner, deadline, or reassessment trigger.
Evidence Quality
Strong evidence use
The fictional source directly addresses the asset, threat, control, time window, and decision being evaluated.
Weak evidence use
A general or unrelated source is used as if it proves the specific risk.
Reviewer question
Does this evidence answer the actual risk question?
Strong evidence use
The fictional source is current, complete enough, accessible, properly scoped, and owned.
Weak evidence use
The source is stale, delayed, partial, unowned, or missing important coverage.
Reviewer question
Can the source be trusted within the stated boundary?
Strong evidence use
Several fictional sources with different origins support the same conclusion.
Weak evidence use
Multiple dashboards, alerts, screenshots, and exports all come from one parent source.
Reviewer question
Are these truly separate sources or repeated views of the same evidence?
Strong evidence use
The fictional evidence matches the current decision window and preserves event, receipt, review, and approval dates.
Weak evidence use
Old evidence is used without checking whether the environment or control changed.
Reviewer question
Is the evidence current enough for this decision?
Strong evidence use
The fictional evidence covers the relevant assets, users, systems, suppliers, regions, controls, and exceptions.
Weak evidence use
Important exclusions, blind spots, dependencies, or populations are omitted.
Reviewer question
What important part of the scenario is outside the evidence?
Strong evidence use
Fictional sources agree or differences are explained through timing, scope, ownership, or method.
Weak evidence use
Conflicting evidence is ignored or one preferred source is accepted without analysis.
Reviewer question
Do the sources tell the same story, and if not, why?
Strong evidence use
Every fictional finding links to exact records, owners, dates, assumptions, calculations, and review notes.
Weak evidence use
The score appears with no explanation of how it was reached.
Reviewer question
Can another reviewer reconstruct the conclusion?
Strong evidence use
Fictional missing data, uncertainty, bias, coverage gaps, assumptions, and alternate explanations are documented.
Weak evidence use
The assessment sounds certain despite incomplete evidence.
Reviewer question
What can this evidence not prove?
Risk Register Design
Purpose
Connects a fictional asset, threat, vulnerability, event path, and consequence in one clear scenario.
Fictional example
Because a supplier account remains active after project closure, the supplier could retain access to confidential support records, causing unauthorized access or delayed detection.
Quality standard
The statement describes a plausible possibility without claiming the event already happened.
Purpose
Estimates fictional scenario plausibility before current controls are considered.
Fictional example
Medium-High because the account exists, the project ended, and the supplier previously required broad access.
Quality standard
The rationale uses evidence and a defined time window.
Purpose
Estimates fictional maximum plausible consequence before current controls are considered.
Fictional example
High because the account could reach confidential support records and affect privacy, trust, and operations.
Quality standard
Potential impact remains separate from confirmed harm.
Purpose
Evaluates how strongly fictional preventive, detective, corrective, recovery, and governance controls reduce the scenario.
Fictional example
Network restriction is healthy, but sponsor review and account expiration controls failed.
Quality standard
Control design and actual operation are evaluated separately.
Purpose
Estimates fictional plausibility after current controls and weaknesses are considered.
Fictional example
Medium because network restriction reduces reach, but the active account and expired exception remain.
Quality standard
The score reflects both controls and their limitations.
Purpose
Estimates fictional consequence after current controls, recovery, detection, and response capabilities are considered.
Fictional example
Medium-High because access scope is limited but confidential data and delayed detection remain possible.
Quality standard
Recovery and detection reduce consequence only when evidence supports their effectiveness.
Purpose
Shows how strongly fictional evidence supports the likelihood and impact judgments.
Fictional example
Medium confidence because account status and scope are known but post-expiration activity logs are incomplete.
Quality standard
Uncertainty changes the wording and review priority rather than being hidden.
Purpose
Assigns fictional decision authority, treatment ownership, due date, reassessment date, and event-based triggers.
Fictional example
Third-Party Risk Owner reviews in seven fictional days or immediately if supplier activity appears.
Quality standard
The risk cannot remain open without an accountable decision and next review.
Risk Register
A fictional supplier account remains active after the related project and exception ended.
Evidence
Account status, expired exception, completed project, sponsor record, access scope, and incomplete post-expiration activity logs.
Risk owner
Third-Party Risk Owner
Evidence limit
No unauthorized sign-in, record access, or disclosure is confirmed.
A fictional service could experience delayed recovery because no business recovery risk owner is confirmed.
Evidence
Criticality record, recovery procedure, operator roster, missing risk owner, recovery objective, and escalation map.
Risk owner
Business Service Executive
Evidence limit
The service may still recover successfully with the existing technical team.
A fictional business unit may retain inappropriate access because its quarterly review is incomplete.
Evidence
Access-review schedule, completed units, incomplete unit, role inventory, owner reminder, and review procedure.
Risk owner
Identity Governance
Evidence limit
No specific inappropriate account or action is confirmed.
Fictional leaders could make poor security decisions because the ninety-eight percent compliance metric excludes undocumented systems.
Evidence
Dashboard, metric definition, asset inventory, excluded-system uncertainty, control records, and owner response.
Risk owner
Security Metrics Owner
Evidence limit
The measured systems may still have strong control performance.
Fictional stale supplier access could recur because an incident improvement action has no assigned policy or procedure owner.
Evidence
Incident review, offboarding recommendation, action tracker, ownership matrix, supplier procedure, and current gap.
Risk owner
Governance Improvement Lead
Evidence limit
Some operational improvement may exist outside the supplied governance records.
Fictional encryption exceptions could be approved inconsistently because the standard does not name a validation owner.
Evidence
Encryption standard, exception template, control-owner map, approval path, and review records.
Risk owner
Security Architecture
Evidence limit
No weak encryption or exposed data is confirmed.
A fictional accepted risk could remain unmanaged because its six-month review date passed without renewal or closure evidence.
Evidence
Risk decision, approval, expiration, treatment status, owner record, and missing reassessment.
Risk owner
Executive Risk Owner
Evidence limit
The underlying risk may have changed since the last decision.
Fictional control requirements could become misaligned because the main policy review is overdue while services and suppliers changed.
Evidence
Policy review date, current service inventory, supplier changes, new dependencies, control map, and governance calendar.
Risk owner
Security Policy Owner
Evidence limit
The policy may remain substantively accurate despite the overdue review.
Defensive Workflow
State the asset, business objective, scope, time window, authority, owners, evidence, privacy limits, scoring method, and prohibited real-world use.
Output: Risk-assessment charter.
Map fictional services, data, users, identities, suppliers, processes, facilities, technologies, recovery needs, and dependency chains.
Output: Asset and dependency register.
Connect fictional threats, vulnerabilities, exposure, event paths, control conditions, and potential consequences.
Output: Structured risk-scenario library.
Review fictional relevance, health, independence, timeliness, completeness, consistency, traceability, assumptions, and limitations.
Output: Evidence-quality register.
Score fictional inherent and residual risk using transparent criteria, current controls, business context, uncertainty, and confidence.
Output: Risk scoring rationale.
Compare fictional risk level, criticality, control weakness, uncertainty, dependency, decision deadline, and remediation readiness.
Output: Risk-ranked register.
Document fictional risk owner, treatment owner, evidence owner, due date, escalation, review trigger, and required decision.
Output: Owned risk action plan.
Confirm fictional findings, alternatives, confidence, limitations, leadership meaning, residual risk, reassessment, and portfolio safety.
Output: Reviewed risk-assessment package.
Fake Dashboard
Training dashboard for fictional risk evidence only.
Risk records reviewed
8
Supplier, recovery, identity, metrics, offboarding, encryption, residual-risk, and policy scenarios are mapped.
High-impact scenarios
4
Supplier access, recovery ownership, offboarding recurrence, and encryption exceptions require prioritized review.
Confirmed incidents
0
The supplied fictional evidence supports risk scenarios and control gaps but no confirmed incident or disclosure.
Fake SOC Alert
Source: Fake Risk Assessment Console • Time: 10:15 AM
Fake Log Panel
09:00 CHARTER scope='risk identification and assessment' 09:08 ASSET support-records classification='confidential' 09:15 THREAT stale-supplier-access scenario='plausible' 09:22 VULNERABILITY exception='expired' account='active' 09:29 CONTROL network-scope='limited' sponsor-review='failed' 09:36 EVIDENCE activity-logs='incomplete' 09:43 LIKELIHOOD residual='Medium' 09:50 IMPACT potential='High' confirmed='none' 09:57 CONFIDENCE='Medium-High' 10:04 OWNER third-party-risk='assigned' 10:12 REVIEW trigger='7 days or supplier activity' 10:20 RISK recovery-owner-gap='Medium x High' 10:28 RISK metric-denominator='Medium-High x Medium' 10:36 RISK offboarding-recurrence='Medium-High x High' 10:44 FINDING confirmed_incident='not supported' 10:52 PRIORITY stale-access_and_owner-gaps='first'
Training note: this is fake data for defensive analysis practice only.
Findings Matrix
Evidence support
Exception expiration, account status, project closure, sponsor record, access scope, network restriction, and incomplete activity evidence.
Alternative
The supplier may still have an approved business need that was not documented on time.
Limitation
No unauthorized sign-in, record access, or disclosure is confirmed.
Evidence support
Service criticality, recovery procedure, operator roster, recovery objective, missing risk owner, and escalation map.
Alternative
An informal business owner may exist outside the supplied records.
Limitation
The ownership gap does not prove recovery would fail.
Evidence support
Dashboard, metric definition, asset inventory, excluded-system uncertainty, control records, and metric-owner response.
Alternative
The percentage may be accurate within a narrower undocumented scope.
Limitation
The finding does not prove poor control operation in the measured systems.
Evidence support
Incident recommendation, action tracker, missing owner, supplier access exception, procedure gap, and governance matrix.
Alternative
Operational teams may have changed practice without updating governance evidence.
Limitation
Current supplier offboarding performance is only partially evidenced.
Evidence support
Supplier activity gap, informal-owner possibility, incomplete access review, metric exclusions, and stale decision records.
Alternative
Additional records may raise or lower both likelihood and confidence.
Limitation
Confidence does not directly replace likelihood or impact.
Evidence support
Active supplier account, critical-service owner gap, stale risk acceptance, overdue access review, policy review, and metric ambiguity.
Alternative
Leadership may reorder actions based on current business deadlines or incident conditions.
Limitation
Final priority requires fictional risk-owner approval.
Analyze the Evidence
Common Mistakes
Safe Practice Lab
Your fictional assignment
Use only the supplied fictional Northbridge records to complete an end-to-end risk identification and assessment.
Required deliverables
Scenario Decision Lab
The fictional supplier account remains active after the exception expired, but the supplied logs do not cover the full post-expiration period.
Scenario Decision Lab
The fictional reporting service has technical operators and a tested procedure, but no authorized business owner for recovery risk decisions.
Defender Habits
Check Your Understanding
Choose your answers first. Explanations appear only after submission.
Portfolio Prompt
Create a fictional Risk Identification and Assessment Package for Northbridge. Include the assessment charter, asset and dependency register, risk scenarios, evidence-quality register, assumptions, likelihood and impact criteria, inherent and residual risk, control-effectiveness review, confidence and limitations, risk register, priority rationale, owner and treatment map, reassessment triggers, technical summary, leadership summary, reflection, and a portfolio-safety statement.
Key Takeaways
Navigation