Came across this overview read from a Gartner research note recently. It lays out seven recommended steps managing risk.

- Implement a framework for risk assessment and mapping.
- Establish the responsibilities of risk managers with their areas of responsibility.
- Identify and define the risks to which the business is exposed and what constitutes a risk event or "near miss" so that incidents can be mapped to specific risks.
- Determine the threat level, and focus on those risks with the highest impact on performance.
- Establish levels of controls for processes commensurate with the perceived threat.
- Record and retain risk incident and near-miss information.
- Conduct periodic risk assessments to determine changes in the operations risk profile and assess control performance.





