Beyond SOC 2
What is risk management?
What is risk management?
Risk management is the process of identifying what could stop an organisation meeting its objectives, assessing how likely and how damaging each is, deciding what to do, and checking the decision worked. ISO 31000 is the general standard and defines risk as the effect of uncertainty on objectives, which is why the objectives come first: without them there is no way to say what counts as a risk.
The process
| Step | Question it answers |
|---|---|
| Identify | What could go wrong, and to what? |
| Analyse | How likely, and how bad? |
| Evaluate | Is that acceptable against our risk appetite? |
| Treat | Avoid, reduce, transfer, accept, or share |
| Monitor and review | Did the treatment work, and has anything changed? |
The output of steps one to four is a risk register. Step five is what most programmes drop after the first year.
Risk management, mitigation, and control
These get used interchangeably and are not the same.
- Risk management is the whole process above.
- Risk mitigation, more precisely reduction, is one of five treatments: lowering likelihood or impact through controls.
- A control is the specific safeguard implementing a treatment. MFA is a control; reducing account-takeover risk is the treatment; the register entry is the management.
The five treatments in full: avoid, reduce, transfer, accept, share. See what are the five risk mitigation strategies.
Why compliance frameworks insist on it
Because it is what makes a control set defensible. A company that implements controls without a risk assessment has copied a template, and neither it nor its auditor can say whether those controls address anything the business actually faces.
| Framework | Where it appears |
|---|---|
| SOC 2 | CC3 series, risk identification and analysis |
| ISO 27001 | Clause 6.1, with a documented methodology |
| HIPAA | Security Rule risk analysis, the most frequently cited enforcement gap |
| NIST 800-53 | RA control family |
HIPAA is the sharpest example. A missing or inadequate risk analysis is one of the most common findings in HHS enforcement actions, more so than the technical failures people expect.
Cyber security risk management specifically
Same process, narrowed to information assets and threats. The differences in practice are that the threat landscape changes faster, so review cadence matters more, and that many risks are concentrated in third parties rather than your own systems, which is why vendor risk gets its own register.
The order that gets reversed
Most small compliance programmes start by collecting evidence, then work backwards to controls, and never do the risk assessment at all. That produces evidence for controls nobody chose, and gaps in the ones that mattered. Risk assessment first, controls from the assessment, evidence from the controls.