Risk Identification

Noun · Security & Infosec

Definitions

  1. The process of discovering and naming potential security risks before or while they materialize into incidents. Risk identification can come from threat modeling, audits, architecture reviews, incidents, compliance work, or external intelligence.

    In plain English: Finding and recognizing possible security risks.

    Example: "The architecture workshop focused first on risk identification so the team could see where the new data-sharing feature changed exposure."

Related Terms