Terminology Index
Glossary
1801 terms
Showing 1345-1376 of 1801 terms
Risk Identification
The step of finding and naming the risks an organization faces, through workshops, scans, threat modeling, and other sources, so they can then be analyzed and treated rather than missed entirely.
Risk identification produces the candidate list every risk process needs: what could go wrong, what assets are at stake, what threats apply. Techniques include workshops with stakeholders, threat modeling, scenario analysis, scans, and consulting threat intelligence and prior incidents. Comprehensive identification matters because unrecognized risks can't be managed. As a foundational step in security governance, capstone GRC, and analyst practice, it shapes everything downstream.
Introduced in: Security Governance and Program Foundations, GRC Capstone: Building a Security Program, GRC Analyst Fundamentals
Examples
- Running a workshop with stakeholders to identify risks.
- Using threat modeling and scans to surface risks systematically.
- Consulting incident history to ensure known risks aren't missed.
No related terms linked yet.
