Everything published on IT Risk Guide, in the order in which the work is usually done. Each entry says who it is for and when to read it.
Start here
- The IT risk register: for anyone setting up or repairing a register. Read it first if you are starting from nothing, or if your register exists but nobody opens it. It covers the fields that matter, how to write a risk so it can be scored, who owns what, and how entries go stale.
- Risk scoring: for anyone who must put a number or a band on a risk. Read it before you adopt a scale, or when someone challenges your heat map. It writes the 4 by 4 scale out in full and is direct about the problems with multiplying ordinal scores.
Controls that generate risks and evidence
- Vendor and third-party risk: for IT managers and owner-operators who depend on suppliers for hosting, software or data processing. Read it when a customer, auditor or insurer asks how you control your suppliers, or before you sign with a new Tier 1 supplier.
- Access reviews: for the person who has to run or evidence a periodic review of who can do what. Read it when you are about to start the first review, or when your reviews keep approving everything. It includes read-only commands for common systems.
Decisions and assurance
- Risk treatment and residual risk: for risk owners and managers who have scored risks and now must decide what to do. Read it before a meeting where someone will be asked to accept, fund or avoid a risk.
- Audit preparation: for IT and security managers facing a customer assessment, an insurer’s questionnaire or an independent review. Read it at least a few months before fieldwork, because evidence cannot be created retrospectively.
- Board reporting: for the executive or manager who has a few minutes and a page to put IT risk in front of a board. Read it when drafting the next report.
Tools
- Risk matrix tool: for anyone who wants to turn a list of risks into a ranked, plotted summary quickly. Use it after reading the scoring guide, with your own impact definitions. Its output is a working estimate and not an audit, certification or evidence of compliance.
- Tools overview: a short description of what the tools on this site do and do not do.