Terminology Index

Glossary

1801 terms

Open concept maps

Showing 1345-1376 of 1801 terms

R
32

Risk Identification

The step of finding and naming the risks an organization faces, through workshops, scans, threat modeling, and other sources, so they can then be analyzed and treated rather than missed entirely.

Risk identification produces the candidate list every risk process needs: what could go wrong, what assets are at stake, what threats apply. Techniques include workshops with stakeholders, threat modeling, scenario analysis, scans, and consulting threat intelligence and prior incidents. Comprehensive identification matters because unrecognized risks can't be managed. As a foundational step in security governance, capstone GRC, and analyst practice, it shapes everything downstream.

Introduced in: Security Governance and Program Foundations, GRC Capstone: Building a Security Program, GRC Analyst Fundamentals

Examples

  • Running a workshop with stakeholders to identify risks.
  • Using threat modeling and scans to surface risks systematically.
  • Consulting incident history to ensure known risks aren't missed.

No related terms linked yet.