Home / Insights / Glossary / Information security risk management

Glossary

Information security risk management

Applying risk management to the confidentiality, integrity and availability of information.

What it means

Information security risk management identifies what information matters, what threatens it, what controls apply and what residual exposure remains. ISO 27005 sets out a method; ISO 27001 requires the discipline as part of a management system.

It is distinguished from cyber security by scope: it covers paper, people and process as well as systems, and its output is a management decision rather than a technical fix.

Where MyRISK fits

What we do about it

Where a specific information-security decision may be challenged — a risk accepted, an exception approved, an access model signed off — Trace holds the evidence, authority and conditions behind it. Where the need is a working rhythm rather than a single decision, that is Essentials.

MyRISK Trace

Is this the thing you are actually trying to fix?

A definition rarely settles it. Tell us what happened — the request, the finding, the challenge or the incident — and we will say where to start, or that it isn't us.