Skip to main content

Resources

Everything published on IT Risk Guide, in the order in which the work is usually done. Each entry says who it is for and when to read it.

Start here

  • The IT risk register: for anyone setting up or repairing a register. Read it first if you are starting from nothing, or if your register exists but nobody opens it. It covers the fields that matter, how to write a risk so it can be scored, who owns what, and how entries go stale.
  • Risk scoring: for anyone who must put a number or a band on a risk. Read it before you adopt a scale, or when someone challenges your heat map. It writes the 4 by 4 scale out in full and is direct about the problems with multiplying ordinal scores.

Controls that generate risks and evidence

  • Vendor and third-party risk: for IT managers and owner-operators who depend on suppliers for hosting, software or data processing. Read it when a customer, auditor or insurer asks how you control your suppliers, or before you sign with a new Tier 1 supplier.
  • Access reviews: for the person who has to run or evidence a periodic review of who can do what. Read it when you are about to start the first review, or when your reviews keep approving everything. It includes read-only commands for common systems.

Decisions and assurance

  • Risk treatment and residual risk: for risk owners and managers who have scored risks and now must decide what to do. Read it before a meeting where someone will be asked to accept, fund or avoid a risk.
  • Audit preparation: for IT and security managers facing a customer assessment, an insurer’s questionnaire or an independent review. Read it at least a few months before fieldwork, because evidence cannot be created retrospectively.
  • Board reporting: for the executive or manager who has a few minutes and a page to put IT risk in front of a board. Read it when drafting the next report.

Tools

  • Risk matrix tool: for anyone who wants to turn a list of risks into a ranked, plotted summary quickly. Use it after reading the scoring guide, with your own impact definitions. Its output is a working estimate and not an audit, certification or evidence of compliance.
  • Tools overview: a short description of what the tools on this site do and do not do.

About this site

  • About: what the site is, how the material is written, and what it is not.
  • Contact: what you can ask, and what you should never send.
  • Privacy: what the site does and does not do with visitor information.