What it means
Information security risk management identifies what information matters, what threatens it, what controls apply and what residual exposure remains. ISO 27005 sets out a method; ISO 27001 requires the discipline as part of a management system.
It is distinguished from cyber security by scope: it covers paper, people and process as well as systems, and its output is a management decision rather than a technical fix.
Where MyRISK fits
What we do about it
Where a specific information-security decision may be challenged — a risk accepted, an exception approved, an access model signed off — Trace holds the evidence, authority and conditions behind it. Where the need is a working rhythm rather than a single decision, that is Essentials.
Is this the thing you are actually trying to fix?
A definition rarely settles it. Tell us what happened — the request, the finding, the challenge or the incident — and we will say where to start, or that it isn't us.