Risk Management
Noun · Security & Infosec
Definitions
The ongoing process of identifying, analyzing, prioritizing, treating, and monitoring risks so security decisions align with business realities and threat conditions. Strong risk management ensures issues are addressed deliberately rather than only reacting to whichever finding is loudest or newest.
In plain English: The overall process of understanding and handling security risks.
Example: "The board wanted evidence of mature risk management, not just a growing list of vulnerabilities without ownership or remediation timelines."