Cybersecurity definition
What is Risk Register?
By Cyber Tool Stack Editorial TeamUpdated
Definition
A tracked, living list of an organization's identified risks, each with an owner, likelihood and impact rating, and a treatment plan — the central artifact most GRC programs and audits are built around.
Where Risk Register fits in the security landscape
These beginner lessons use this term while explaining the surrounding security control.
Related cybersecurity terms
GRCGovernance, Risk, and ComplianceThe combined discipline of setting policy (governance), identifying and managing what could go wrong (risk), and proving adherence to laws and standards (compliance) — usually the umbrella term for the programs and tools that manage all three together.Tabletop ExerciseA discussion-based walkthrough of a simulated incident, where stakeholders talk through their planned response step by step, used to find gaps in an incident response plan before a real breach forces the issue.