Security risk inside enterprise risk management
Where the security register meets the enterprise one: what must agree, what may differ, who owns aggregation, and which rules force the join.
Risk5 Sept 20269 min read
On this page
What it is
Enterprise risk management is the whole-organisation arrangement. ISO 31000:2018 sets it out in two halves. Clause 5 is the framework: leadership and commitment, integration, design, implementation, evaluation and improvement 1. Clause 6 is the process applied within a stated scope, from context and criteria through assessment, treatment, monitoring and reporting 2.
Its effect depends on being built into governance and decision-making 3. Risk management belongs inside purpose, strategy, objectives and operations, not beside them 4.
Information security risk is one taxonomy inside that arrangement, kept in the risk register. ISO/IEC 27001:2022 clause 6.1 is "Actions to address risks and opportunities", with 6.1.2 risk assessment and 6.1.3 risk treatment 5. Neither standard names a winner. The join is governance's decision; security risk supplies the taxonomy; compliance evidences both.
Who is in scope (decision test)
Five questions. The written answers are the record; the fifth settles the rest.
- Is there an enterprise risk register, and a body that reviews it? ISO 31000:2018 asks top management and oversight bodies to make risk management part of all organisational activities, with matching authority 6.
- Does the security register use the enterprise scales, or its own? Criteria state the amount and type of risk that may be taken, and how the level of risk is determined 7.
- Who owns aggregation? Name the role turning many security rows into one enterprise category. Authorities, responsibilities and accountabilities are assigned and communicated at all levels 8.
- Is security reported as a category, or as a list? Reporting is part of governance and supports oversight bodies in meeting their responsibilities 9. No board decides against a list of rows; see board reporting.
- Does a rule require the join? DORA has financial entities hold an ICT risk management framework as part of their overall risk management system 10. NIS2 asks for measures appropriate and proportionate to the risks posed, judged on exposure, size and incident likelihood and severity 11.
| Outcome | What it means | Next step |
|---|---|---|
| One register | Security rows sit in the enterprise register, on enterprise scales | Tag them, then test the scales against exposure |
| Two registers, bridged | Two registers, one mapping, one aggregation owner | Publish the bridge below, review it each cycle |
| Two registers, no bridge | The failure state: two answers, neither reconciled | Settle criteria and ownership before the next cycle |
The bridge
Two registers are legitimate. Two unreconciled registers are a finding. The bridge names what must agree.
One loop, not three silos. The governance decision is how much risk may be taken, and who says so. It belongs to top management and oversight bodies, who set the mandate and the resources 12. The risk instrument is the shared criteria set: the scales, the level-of-risk rule and the evaluation step comparing analysis against them 13. What compliance later demonstrates is that both registers ran on those criteria. It also shows legal and contractual requirements kept current 14. An independent review of the approach then reaches the same picture 15.
| ERM element (ISO 31000:2018) | Security counterpart | What must agree | What may differ | Who decides |
|---|---|---|---|---|
| 5.2 Leadership and commitment 6 | Control 5.4 Management responsibilities 16 | The mandate; how much risk may be taken | Forum names | Top management |
| 5.3 Integration 4 | Clause 6.1 17 | One route from security row to enterprise decision | Where each is documented | Top management |
| 5.4.3 Assigning organizational roles, authorities, responsibilities and accountabilities 8 | Clause 5.3 18 | One named owner per risk, same name in both | Titles, delegation | The risk committee |
| 6.3.4 Defining risk criteria 7 | Clause 3.1.7 risk criteria 19 | Consequence scale, likelihood scale, level rule | Technical sub-criteria | The board |
| 6.4 Risk assessment 20 | Clause 8.2 21 | What "high" means; the escalation threshold | Method, granularity | The risk officer |
| 6.5 Risk treatment 22 | Clause 6.1.3 23 | Which role accepts which residual level, and for how long | Option wording | The board |
| 6.6 Monitoring and review 24 | Clause 9.1 25 | Triggers forcing an out-of-cycle re-assessment | Review frequency | The risk officer |
| 6.7 Recording and reporting 9 | Clause 9.3 26 | Cadence; what reaches the board pack | Annex depth | The risk committee |
The criteria method is in Risk appetite and criteria; the acceptance rule in Risk acceptance and residual risk.
Aggregation without distortion
An enterprise category is fed by the security register, not computed from it. Levels of risk are ordinal. Summing them yields a meaningless number; averaging them hides the row that matters.
Three feeds work. Top-n by level sends rows above the escalation threshold upward unchanged, with owner and date. Threshold breach turns a category amber when a stated count of rows crosses a stated level, and publishes the rule with the count. Indicator movement reads a leading number against its own baseline (Key risk indicators).
Appetite decides which feed fires. It states the amount and type of risk that may be taken relative to objectives, and the criteria that judge significance 7. Evaluation compares analysis against those criteria to see whether further action is needed 13. Without it, the colour is chosen by whoever built the slide.
Reporting belongs to governance and should improve the dialogue with stakeholders 9, so a category carries its rule. CSF 2.0 has GV.RM-06 establish and communicate a standard method for calculating, documenting, categorising and prioritising cybersecurity risks 27.
Dates (verified)
Only application facts already verified for the two instruments above.
Five further passages shape the join and add no date. Under DORA the management body owns every arrangement in the ICT risk framework 32; that framework protects information and ICT assets through stated strategies, policies, procedures, protocols and tools 33; and ICT risk oversight sits with an independent control function outside microenterprises 34. NIS2 has management bodies approve the measures and oversee implementation 35, all-hazards and reaching the physical environment of the systems 36. Its physical counterpart is CER: critical entities assess the natural and man-made risks that could disrupt their essential services, at least every four years 37.
Mapping to ISO/IEC 27001 and NIST CSF 2.0
| ERM step | ISO/IEC 27001:2022 | NIST CSF 2.0 | Gap |
|---|---|---|---|
| Context and obligations | 4.1, 4.2 38 | GV.OC-01, GV.OC-03 39 | Neither names the register holding the obligation |
| Appetite and criteria | 6.1 17 | GV.RM-01, GV.RM-02 40 | No scale, no reconciliation rule |
| Security inside the enterprise process | 6.1.2 41 | GV.RM-03 42 | The outcome is named, not the mechanism |
| Assess and prioritise | 8.2 21 | ID.RA-05, ID.RA-06 43 | No rule from row to category |
| Review and adjust | 9.3.3 44 | GV.OV-01, GV.OV-03 45 | Two strategies reviewed, neither reconciled |
Both assume the reconciliation decision is taken; neither hands it over.
Next 90 days
| Week | Action | Owner | Output |
|---|---|---|---|
| 1-2 | Answer the five questions, then list every divergence between the criteria sets | Risk officer | Decision-test sheet; divergence list |
| 2-3 | Settle the shared scales and the level rule | Risk committee | Approved criteria set, one version |
| 3-4 | Name the aggregation owner, publish the feed rule | Risk committee | Aggregation rule, one page |
| 4-6 | Re-score the security register on the shared scales | Security officer | Re-scored register, movement note |
| 6-8 | Reconcile owners so one name carries each risk | ISMS manager | Owner map, exceptions listed |
| 8-10 | Set the escalation threshold and the out-of-cycle triggers | Risk officer | Threshold statement |
| 10-12 | Report one category to the board, rule attached | Security officer | Board minute, decision recorded |
References
- ISO. Risk management — Guidelines. ISO 31000:2018. Clauses 3, 5, 6, licensed copy, 2026-09-05. https://www.iso.org/standard/65694.html
- ISO/IEC. Information security management systems — Requirements. ISO/IEC 27001:2022. Clause titles, ISO Online Browsing Platform, 2026-09-03. https://www.iso.org/standard/27001
- ISO/IEC. Information security controls. ISO/IEC 27002:2022. Controls 5.4, 5.31, 5.35, licensed copy, 2026-09-05. https://www.iso.org/standard/75652.html
- ISO/IEC. Managing information security risks. ISO/IEC 27005:2022. Clause 3, publisher preview, 2026-09-05. https://www.iso.org/standard/80585.html
- NIST. The NIST Cybersecurity Framework (CSF) 2.0. NIST CSWP 29, 26 February 2024, Appendix A. Read 2026-09-05. https://doi.org/10.6028/NIST.CSWP.29
- Regulation (EU) 2022/2554 (DORA). CELEX 32022R2554, Cellar, 2026-09-05. https://eur-lex.europa.eu/eli/reg/2022/2554/oj/eng
- Directive (EU) 2022/2555 (NIS2). CELEX 32022L2555, Cellar, 2026-09-05. https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng
- Directive (EU) 2022/2557 (CER). CELEX 32022L2557, Cellar, 2026-09-05. https://eur-lex.europa.eu/eli/dir/2022/2557/oj/eng
Standards and certification names are the property of their respective owners. GRCIDE is an independent publication and is not affiliated with, authorized, sponsored or endorsed by ISO, IEC, NIST or any other standards body.
Sources
- 1ISO 31000:2018 clause 5, licensed copy · verified 2026-09-05
- 2ISO 31000:2018 clause 6.1, licensed copy · verified 2026-09-05
- 3ISO 31000:2018 clause 5.1, licensed copy · verified 2026-09-05
- 4ISO 31000:2018 clause 5.3, licensed copy · verified 2026-09-05
- 5ISO/IEC 27001:2022 clauses 6.1, 6.1.2 and 6.1.3, iso.org/obp · verified 2026-09-03
- 6ISO 31000:2018 clause 5.2, licensed copy · verified 2026-09-05
- 7ISO 31000:2018 clause 6.3.4, licensed copy · verified 2026-09-05
- 8ISO 31000:2018 clause 5.4.3, licensed copy · verified 2026-09-05
- 9ISO 31000:2018 clause 6.7, licensed copy · verified 2026-09-05
- 10EU Publications Office CELEX 32022R2554 Art. 6(1) · verified 2026-09-05
- 11EU Publications Office CELEX 32022L2555 Art. 21(1) · verified 2026-09-05
- 12ISO 31000:2018 clauses 5.2 and 5.4.4, licensed copy · verified 2026-09-05
- 13ISO 31000:2018 clause 6.4.4, licensed copy · verified 2026-09-05
- 14ISO/IEC 27002:2022 control 5.31, licensed copy · verified 2026-09-05
- 15ISO/IEC 27002:2022 control 5.35, licensed copy · verified 2026-09-05
- 16ISO/IEC 27002:2022 control 5.4, licensed copy · verified 2026-09-05
- 17ISO/IEC 27001:2022 clause 6.1, iso.org/obp · verified 2026-09-03
- 18ISO/IEC 27001:2022 clause 5.3, iso.org/obp · verified 2026-09-03
- 19ISO/IEC 27005:2022 clause 3.1.7, publisher preview · verified 2026-09-05
- 20ISO 31000:2018 clauses 6.4 and 6.4.3, licensed copy · verified 2026-09-05
- 21ISO/IEC 27001:2022 clause 8.2, iso.org/obp · verified 2026-09-03
- 22ISO 31000:2018 clauses 6.5 and 6.5.2, licensed copy · verified 2026-09-05
- 23ISO/IEC 27001:2022 clause 6.1.3, iso.org/obp · verified 2026-09-03
- 24ISO 31000:2018 clause 6.6, licensed copy · verified 2026-09-05
- 25ISO/IEC 27001:2022 clause 9.1, iso.org/obp · verified 2026-09-03
- 26ISO/IEC 27001:2022 clause 9.3, iso.org/obp · verified 2026-09-03
- 27NIST CSWP 29 Appendix A GV.RM-06, nvlpubs.nist.gov · verified 2026-09-05
- 28EUR-Lex CELEX 32022L2555 Art. 45 and 38(2) · verified 2026-09-03
- 29EUR-Lex CELEX 32022L2555 Art. 41(1) and 21(5) · verified 2026-09-03
- 30EUR-Lex CELEX 32022L2555 Art. 41(1) and 44 · verified 2026-09-03
- 31EU Publications Office CELEX 32022R2554 Art. 64 · verified 2026-09-05
- 32EU Publications Office CELEX 32022R2554 Art. 5(2) · verified 2026-09-05
- 33EU Publications Office CELEX 32022R2554 Art. 6(2) · verified 2026-09-05
- 34EU Publications Office CELEX 32022R2554 Art. 6(4) · verified 2026-09-05
- 35EU Publications Office CELEX 32022L2555 Art. 20(1) · verified 2026-09-05
- 36EU Publications Office CELEX 32022L2555 Art. 21(2) · verified 2026-09-05
- 37EU Publications Office CELEX 32022L2557 Art. 12(1) and 12(2) · verified 2026-09-05
- 38ISO/IEC 27001:2022 clauses 4.1 and 4.2, iso.org/obp · verified 2026-09-03
- 39NIST CSWP 29 Appendix A GV.OC-01 and GV.OC-03, nvlpubs.nist.gov · verified 2026-09-05
- 40NIST CSWP 29 Appendix A GV.RM-01 and GV.RM-02, nvlpubs.nist.gov · verified 2026-09-05
- 41ISO/IEC 27001:2022 clause 6.1.2, iso.org/obp · verified 2026-09-03
- 42NIST CSWP 29 Appendix A GV.RM-03, nvlpubs.nist.gov · verified 2026-09-05
- 43NIST CSWP 29 Appendix A ID.RA-05 and ID.RA-06, nvlpubs.nist.gov · verified 2026-09-05
- 44ISO/IEC 27001:2022 clause 9.3.3, iso.org/obp · verified 2026-09-03
- 45NIST CSWP 29 Appendix A GV.OV-01 and GV.OV-03, nvlpubs.nist.gov · verified 2026-09-05