Deep Dive - Risk Register
Show your auditor how mature your security practices are
Written By Micah
What is a Risk Register?
A risk register is the result of your risk assessment, in list form. When you export your risk assessment from your Strike Graph account, we create the risk register for you! Under the column “active controls'' you'll see all of the controls from your unique control library you have assigned to mitigate each applicable risk.
Which framework is this for?
SOC 2, HIPAA
Why is this evidence item important?
Not only is this an audit requirement, but it shows that you have considered risks to your organization and how to mitigate them. Performing a risk assessment is foundational to your business and the Register serves as a means to show your leadership and auditors that you have been thoughtful and efficient in determining the controls you have put in place.
Who participates in the related control?
Typical parties involved: C-Suite and management team, as they know the company holistically. You may find that for specific risks, you need to pull in folks from that department or with related expertise.
How often should I monitor or update the risk register?
Typical Frequency: You should review and update your risk assessment and register annually. It’s best practice to review and update your risk scores 30-45 days before your next SOC 2 audit. Once you’ve done this, export your updated scores, and upload them in the evidence library.
How do I perform this control?
The first time you take your risk assessment: Score each risk as if you had no controls in place to mitigate it. What would be the hypothetical impact to your business?
The next time you take your risk assessment, once you have already completed your first SOC 2 audit: Score each risk with your mitigating controls in mind. Is the impact of the risk lower this time around?