Does your organization use standardized templates or tools to document and track cybersecurity risk information?
Explanation
Using standardized templates like risk registers ensures consistent documentation of risk details including descriptions, potential impact, mitigation strategies, and ownership. This structured approach helps organizations maintain visibility of their risk landscape, track remediation efforts, and support informed decision-making about resource allocation.
Evidence could include a sample risk register template (with sensitive information redacted), screenshots of a risk management tool, or documentation showing the organization's risk documentation methodology and how it's implemented across the enterprise.
Implementation Example
Create and use templates (e.g., a risk register) to document cybersecurity risk information (e.g., risk description, exposure, treatment, and ownership)
ID: GV.RM-06.027
Context
- Function
- GV: GOVERN
- Category
- GV.RM: Risk Management Strategy
- Sub-Category
- A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated
Related questions
- Does your organization update cybersecurity risk management objectives as part of annual strategic planning and when significant organizational or environmental changes occur?
- Has your organization established measurable objectives for cybersecurity risk management?
- Have senior leaders established and agreed upon measurable cybersecurity objectives that are used to manage risk and evaluate performance?
- Has your organization formally defined and communicated risk appetite statements that clearly articulate acceptable levels of risk across different business areas?
- Has your organization translated high-level risk appetite statements into specific, measurable risk tolerance metrics that can be monitored and reported?
- Does your organization have a formal process to periodically review and update its risk appetite and objectives based on current risk exposure and residual risk levels?

