Risk Management

Kind: activity

Layer: Security Core

Record: architecture:risk-management

Severity: contextual

Scope: architecture, security, delivery

Canonical: Ontology

The activity of identifying risks, rating their likelihood and impact, and assigning each one an owner and a mitigation.

Listed in Architecture principles, after Policy as Code and before Continuous Compliance.

Requires

Reinforces

Enables

Conflicts with

In tension with

Tensions

Violated by

Refactored by

Severity

Category

Reinforced by

Linked from