Risk Assessment · 06
Risk Assessment
- Client
- Confidential Client
- Role
- GRC Analyst
- Year
- 2025
- Category
- Risk Assessment
Overview
A formal information-security risk assessment identifying, analyzing and prioritizing risk across systems, vendors and business processes to inform treatment decisions and resourcing.
Key Activities
- Identified assets, threats and vulnerabilities across the environment
- Scored risks by likelihood and impact against a defined risk matrix
- Evaluated third-party and vendor risk exposure
- Presented findings and a treatment plan to leadership
Outcome
Gave leadership a prioritized, evidence-based risk register and treatment plan to guide security investment.
Frameworks & Standards
ISO/IEC 27005NIST CSFInternal risk register