Back to briefings
    Briefing

    Security risk inside enterprise risk management

    Where the security register meets the enterprise one: what must agree, what may differ, who owns aggregation, and which rules force the join.

    Risk5 Sept 20269 min read

    Directive (EU) 2022/2555Directive (EU) 2022/2557ISO 31000:2018ISO/IEC 27001:2022ISO/IEC 27002:2022ISO/IEC 27005:2022NIST CSWP 29Regulation (EU) 2022/2554
    On this page

    What it is

    Enterprise risk management is the whole-organisation arrangement. ISO 31000:2018 sets it out in two halves. Clause 5 is the framework: leadership and commitment, integration, design, implementation, evaluation and improvement 1. Clause 6 is the process applied within a stated scope, from context and criteria through assessment, treatment, monitoring and reporting 2.

    Its effect depends on being built into governance and decision-making 3. Risk management belongs inside purpose, strategy, objectives and operations, not beside them 4.

    Information security risk is one taxonomy inside that arrangement, kept in the risk register. ISO/IEC 27001:2022 clause 6.1 is "Actions to address risks and opportunities", with 6.1.2 risk assessment and 6.1.3 risk treatment 5. Neither standard names a winner. The join is governance's decision; security risk supplies the taxonomy; compliance evidences both.

    Who is in scope (decision test)

    Five questions. The written answers are the record; the fifth settles the rest.

    1. Is there an enterprise risk register, and a body that reviews it? ISO 31000:2018 asks top management and oversight bodies to make risk management part of all organisational activities, with matching authority 6.
    2. Does the security register use the enterprise scales, or its own? Criteria state the amount and type of risk that may be taken, and how the level of risk is determined 7.
    3. Who owns aggregation? Name the role turning many security rows into one enterprise category. Authorities, responsibilities and accountabilities are assigned and communicated at all levels 8.
    4. Is security reported as a category, or as a list? Reporting is part of governance and supports oversight bodies in meeting their responsibilities 9. No board decides against a list of rows; see board reporting.
    5. Does a rule require the join? DORA has financial entities hold an ICT risk management framework as part of their overall risk management system 10. NIS2 asks for measures appropriate and proportionate to the risks posed, judged on exposure, size and incident likelihood and severity 11.
    OutcomeWhat it meansNext step
    One registerSecurity rows sit in the enterprise register, on enterprise scalesTag them, then test the scales against exposure
    Two registers, bridgedTwo registers, one mapping, one aggregation ownerPublish the bridge below, review it each cycle
    Two registers, no bridgeThe failure state: two answers, neither reconciledSettle criteria and ownership before the next cycle

    The bridge

    Two registers are legitimate. Two unreconciled registers are a finding. The bridge names what must agree.

    One loop, not three silos. The governance decision is how much risk may be taken, and who says so. It belongs to top management and oversight bodies, who set the mandate and the resources 12. The risk instrument is the shared criteria set: the scales, the level-of-risk rule and the evaluation step comparing analysis against them 13. What compliance later demonstrates is that both registers ran on those criteria. It also shows legal and contractual requirements kept current 14. An independent review of the approach then reaches the same picture 15.

    ERM element (ISO 31000:2018)Security counterpartWhat must agreeWhat may differWho decides
    5.2 Leadership and commitment 6Control 5.4 Management responsibilities 16The mandate; how much risk may be takenForum namesTop management
    5.3 Integration 4Clause 6.1 17One route from security row to enterprise decisionWhere each is documentedTop management
    5.4.3 Assigning organizational roles, authorities, responsibilities and accountabilities 8Clause 5.3 18One named owner per risk, same name in bothTitles, delegationThe risk committee
    6.3.4 Defining risk criteria 7Clause 3.1.7 risk criteria 19Consequence scale, likelihood scale, level ruleTechnical sub-criteriaThe board
    6.4 Risk assessment 20Clause 8.2 21What "high" means; the escalation thresholdMethod, granularityThe risk officer
    6.5 Risk treatment 22Clause 6.1.3 23Which role accepts which residual level, and for how longOption wordingThe board
    6.6 Monitoring and review 24Clause 9.1 25Triggers forcing an out-of-cycle re-assessmentReview frequencyThe risk officer
    6.7 Recording and reporting 9Clause 9.3 26Cadence; what reaches the board packAnnex depthThe risk committee

    The criteria method is in Risk appetite and criteria; the acceptance rule in Risk acceptance and residual risk.

    Aggregation without distortion

    An enterprise category is fed by the security register, not computed from it. Levels of risk are ordinal. Summing them yields a meaningless number; averaging them hides the row that matters.

    Three feeds work. Top-n by level sends rows above the escalation threshold upward unchanged, with owner and date. Threshold breach turns a category amber when a stated count of rows crosses a stated level, and publishes the rule with the count. Indicator movement reads a leading number against its own baseline (Key risk indicators).

    Appetite decides which feed fires. It states the amount and type of risk that may be taken relative to objectives, and the criteria that judge significance 7. Evaluation compares analysis against those criteria to see whether further action is needed 13. Without it, the colour is chosen by whoever built the slide.

    Reporting belongs to governance and should improve the dialogue with stakeholders 9, so a category carries its rule. CSF 2.0 has GV.RM-06 establish and communicate a standard method for calculating, documenting, categorising and prioritising cybersecurity risks 27.

    Dates (verified)

    Only application facts already verified for the two instruments above.

    DateWhat happensSource
    2023-01-16NIS2 enters into force, twenty days after publication28
    2024-10-17NIS2 transposition deadline29
    2024-10-18Member States apply the measures; Directive (EU) 2016/1148 repealed30
    2025-01-17DORA applies31

    Five further passages shape the join and add no date. Under DORA the management body owns every arrangement in the ICT risk framework 32; that framework protects information and ICT assets through stated strategies, policies, procedures, protocols and tools 33; and ICT risk oversight sits with an independent control function outside microenterprises 34. NIS2 has management bodies approve the measures and oversee implementation 35, all-hazards and reaching the physical environment of the systems 36. Its physical counterpart is CER: critical entities assess the natural and man-made risks that could disrupt their essential services, at least every four years 37.

    Mapping to ISO/IEC 27001 and NIST CSF 2.0

    ERM stepISO/IEC 27001:2022NIST CSF 2.0Gap
    Context and obligations4.1, 4.2 38GV.OC-01, GV.OC-03 39Neither names the register holding the obligation
    Appetite and criteria6.1 17GV.RM-01, GV.RM-02 40No scale, no reconciliation rule
    Security inside the enterprise process6.1.2 41GV.RM-03 42The outcome is named, not the mechanism
    Assess and prioritise8.2 21ID.RA-05, ID.RA-06 43No rule from row to category
    Review and adjust9.3.3 44GV.OV-01, GV.OV-03 45Two strategies reviewed, neither reconciled

    Both assume the reconciliation decision is taken; neither hands it over.

    Next 90 days

    WeekActionOwnerOutput
    1-2Answer the five questions, then list every divergence between the criteria setsRisk officerDecision-test sheet; divergence list
    2-3Settle the shared scales and the level ruleRisk committeeApproved criteria set, one version
    3-4Name the aggregation owner, publish the feed ruleRisk committeeAggregation rule, one page
    4-6Re-score the security register on the shared scalesSecurity officerRe-scored register, movement note
    6-8Reconcile owners so one name carries each riskISMS managerOwner map, exceptions listed
    8-10Set the escalation threshold and the out-of-cycle triggersRisk officerThreshold statement
    10-12Report one category to the board, rule attachedSecurity officerBoard minute, decision recorded

    References

    1. ISO. Risk management — Guidelines. ISO 31000:2018. Clauses 3, 5, 6, licensed copy, 2026-09-05. https://www.iso.org/standard/65694.html
    2. ISO/IEC. Information security management systems — Requirements. ISO/IEC 27001:2022. Clause titles, ISO Online Browsing Platform, 2026-09-03. https://www.iso.org/standard/27001
    3. ISO/IEC. Information security controls. ISO/IEC 27002:2022. Controls 5.4, 5.31, 5.35, licensed copy, 2026-09-05. https://www.iso.org/standard/75652.html
    4. ISO/IEC. Managing information security risks. ISO/IEC 27005:2022. Clause 3, publisher preview, 2026-09-05. https://www.iso.org/standard/80585.html
    5. NIST. The NIST Cybersecurity Framework (CSF) 2.0. NIST CSWP 29, 26 February 2024, Appendix A. Read 2026-09-05. https://doi.org/10.6028/NIST.CSWP.29
    6. Regulation (EU) 2022/2554 (DORA). CELEX 32022R2554, Cellar, 2026-09-05. https://eur-lex.europa.eu/eli/reg/2022/2554/oj/eng
    7. Directive (EU) 2022/2555 (NIS2). CELEX 32022L2555, Cellar, 2026-09-05. https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng
    8. Directive (EU) 2022/2557 (CER). CELEX 32022L2557, Cellar, 2026-09-05. https://eur-lex.europa.eu/eli/dir/2022/2557/oj/eng

    Standards and certification names are the property of their respective owners. GRCIDE is an independent publication and is not affiliated with, authorized, sponsored or endorsed by ISO, IEC, NIST or any other standards body.

    Sources

    1. 1ISO 31000:2018 clause 5, licensed copy · verified 2026-09-05
    2. 2ISO 31000:2018 clause 6.1, licensed copy · verified 2026-09-05
    3. 3ISO 31000:2018 clause 5.1, licensed copy · verified 2026-09-05
    4. 4ISO 31000:2018 clause 5.3, licensed copy · verified 2026-09-05
    5. 5ISO/IEC 27001:2022 clauses 6.1, 6.1.2 and 6.1.3, iso.org/obp · verified 2026-09-03
    6. 6ISO 31000:2018 clause 5.2, licensed copy · verified 2026-09-05
    7. 7ISO 31000:2018 clause 6.3.4, licensed copy · verified 2026-09-05
    8. 8ISO 31000:2018 clause 5.4.3, licensed copy · verified 2026-09-05
    9. 9ISO 31000:2018 clause 6.7, licensed copy · verified 2026-09-05
    10. 10EU Publications Office CELEX 32022R2554 Art. 6(1) · verified 2026-09-05
    11. 11EU Publications Office CELEX 32022L2555 Art. 21(1) · verified 2026-09-05
    12. 12ISO 31000:2018 clauses 5.2 and 5.4.4, licensed copy · verified 2026-09-05
    13. 13ISO 31000:2018 clause 6.4.4, licensed copy · verified 2026-09-05
    14. 14ISO/IEC 27002:2022 control 5.31, licensed copy · verified 2026-09-05
    15. 15ISO/IEC 27002:2022 control 5.35, licensed copy · verified 2026-09-05
    16. 16ISO/IEC 27002:2022 control 5.4, licensed copy · verified 2026-09-05
    17. 17ISO/IEC 27001:2022 clause 6.1, iso.org/obp · verified 2026-09-03
    18. 18ISO/IEC 27001:2022 clause 5.3, iso.org/obp · verified 2026-09-03
    19. 19ISO/IEC 27005:2022 clause 3.1.7, publisher preview · verified 2026-09-05
    20. 20ISO 31000:2018 clauses 6.4 and 6.4.3, licensed copy · verified 2026-09-05
    21. 21ISO/IEC 27001:2022 clause 8.2, iso.org/obp · verified 2026-09-03
    22. 22ISO 31000:2018 clauses 6.5 and 6.5.2, licensed copy · verified 2026-09-05
    23. 23ISO/IEC 27001:2022 clause 6.1.3, iso.org/obp · verified 2026-09-03
    24. 24ISO 31000:2018 clause 6.6, licensed copy · verified 2026-09-05
    25. 25ISO/IEC 27001:2022 clause 9.1, iso.org/obp · verified 2026-09-03
    26. 26ISO/IEC 27001:2022 clause 9.3, iso.org/obp · verified 2026-09-03
    27. 27NIST CSWP 29 Appendix A GV.RM-06, nvlpubs.nist.gov · verified 2026-09-05
    28. 28EUR-Lex CELEX 32022L2555 Art. 45 and 38(2) · verified 2026-09-03
    29. 29EUR-Lex CELEX 32022L2555 Art. 41(1) and 21(5) · verified 2026-09-03
    30. 30EUR-Lex CELEX 32022L2555 Art. 41(1) and 44 · verified 2026-09-03
    31. 31EU Publications Office CELEX 32022R2554 Art. 64 · verified 2026-09-05
    32. 32EU Publications Office CELEX 32022R2554 Art. 5(2) · verified 2026-09-05
    33. 33EU Publications Office CELEX 32022R2554 Art. 6(2) · verified 2026-09-05
    34. 34EU Publications Office CELEX 32022R2554 Art. 6(4) · verified 2026-09-05
    35. 35EU Publications Office CELEX 32022L2555 Art. 20(1) · verified 2026-09-05
    36. 36EU Publications Office CELEX 32022L2555 Art. 21(2) · verified 2026-09-05
    37. 37EU Publications Office CELEX 32022L2557 Art. 12(1) and 12(2) · verified 2026-09-05
    38. 38ISO/IEC 27001:2022 clauses 4.1 and 4.2, iso.org/obp · verified 2026-09-03
    39. 39NIST CSWP 29 Appendix A GV.OC-01 and GV.OC-03, nvlpubs.nist.gov · verified 2026-09-05
    40. 40NIST CSWP 29 Appendix A GV.RM-01 and GV.RM-02, nvlpubs.nist.gov · verified 2026-09-05
    41. 41ISO/IEC 27001:2022 clause 6.1.2, iso.org/obp · verified 2026-09-03
    42. 42NIST CSWP 29 Appendix A GV.RM-03, nvlpubs.nist.gov · verified 2026-09-05
    43. 43NIST CSWP 29 Appendix A ID.RA-05 and ID.RA-06, nvlpubs.nist.gov · verified 2026-09-05
    44. 44ISO/IEC 27001:2022 clause 9.3.3, iso.org/obp · verified 2026-09-03
    45. 45NIST CSWP 29 Appendix A GV.OV-01 and GV.OV-03, nvlpubs.nist.gov · verified 2026-09-05