Risk Framework
Noun · Security & Infosec
Definitions
A structured model for identifying, evaluating, treating, and tracking risk across an organization. Risk frameworks provide common terminology, roles, scoring logic, and decision processes so risk is handled consistently rather than ad hoc.
In plain English: A structured way for an organization to manage risk consistently.
Example: "The organization adopted a formal risk framework to align product, infrastructure, and vendor reviews under the same scoring and approval model."