One-page risk picture
A one-page board view of five to seven risks, each with an owner role, a position against appetite, a trend and the decision the body is asked to take.
Governance5 Sept 20263 min read
On this page
one-page-risk-picture.xlsx · 10 kBLicensed CC BY 4.0
What this is
The page a board or executive committee decides from. One sheet holds five to seven risks, each with an owner role, a position against appetite, a trend and the decision requested. Two supporting sheets hold the measures behind the page and the decisions taken across cycles. It is the artefact produced by section 3.5 of Board and management reporting for security, and it answers one question: what does this body have to decide today?
How to use it
- Delete the example rows. Every one is invented and prefixed EXAMPLE - delete.
- Select five to seven rows from the register. Choose on materiality and movement, not on score alone. See the playbook, section 3.3.
- Write each risk as source, event and consequence. The analysis stays in the risk register; this sheet carries the summary.
- Set the position against appetite from the approved criteria. Clause 6.1.2 is titled "Information security risk assessment" 1. The column is a closed list: 1. Within, 2. At, 3. Beyond.
- Attach a decision to every row beyond appetite. Either a funded treatment or a dated acceptance, under clause 6.1.3, "Information security risk treatment" 2. See the playbook, section 3.3.
- Fill the Metrics sheet with measures that force decisions. Clause 9.1 is titled "Monitoring, measurement, analysis and evaluation" 3. See the playbook, section 3.4.
- File the page as a management review input, at clause 9.3.2, and record the results at clause 9.3.3 4 5. See the playbook, section 3.6.
- Carry every open decision forward in the Decision log until it closes on evidence. See the playbook, section 3.7.
What good looks like
Six of the ten columns, from the rows shipped in the workbook.
| ID | Position against appetite | Trend | Owner (role) | Decision requested | Decision taken |
|---|---|---|---|---|---|
| R-001 | 3. Beyond | 3. Worsening | Head of platform engineering | Fund automated deprovisioning, or accept with a named expiry | — |
| R-002 | 2. At | 2. Stable | Head of customer operations | Approve the budget to cost and test an exit route | — |
| R-003 | 1. Within | 1. Improving | Head of infrastructure | None this cycle; reported for information | Noted, with quarterly restore tests confirmed |
Fields
| Field | Required | Meaning | Common mistake |
|---|---|---|---|
| Risk statement | yes | Source, event and consequence in one sentence | Naming a missing control instead of a risk |
| Business impact | yes | What the organisation loses | Restating the technical failure |
| Position against appetite | yes | Within, at or beyond the approved appetite | A score where no criteria were approved |
| Trend | yes | Direction since the last cycle | Leaving it blank on rows that did not move |
| Owner (role) | yes | The role accountable, never a person | The security function standing in for the owner |
| Decision requested | yes beyond appetite | The choice put to the body, with its options | An update dressed as a decision |
| Decision taken, Date | yes to close | What the body decided, and when | A decision recorded with no date and no deciding role |
Rows whose decision follows a nonconformity close under clause 10.2, "Nonconformity and corrective action" 6.
Download
- File:
one-page-risk-picture.xlsx(xlsx, 10 KB) — sheets Read first, Risk picture, Metrics and Decision log. - Markdown variant: the same tables in plain markdown, at
content/templates/assets/_one-page-risk-picture.md. - Licence: CC BY 4.0 — reuse and adapt with attribution to GRCIDE.
- Version: 1.0, 2026-09-05. No personal data, no organisation names, no macros.
Related
- Playbook: Board and management reporting for security
- Playbook: The risk register other people trust
- Template: Risk register, which this page reports from
References
- ISO/IEC. Information security, cybersecurity and privacy protection — Information security management systems — Requirements. ISO/IEC 27001:2022. Contents and clause titles read at https://www.iso.org/obp/ui/#iso:std:iso-iec:27001:ed-3:v1:en 7
Standards and certification names are the property of their respective owners. GRCIDE is an independent publication and is not affiliated with, authorized, sponsored or endorsed by ISO, IEC, NIST or any other standards body.
Sources
- 1ISO/IEC 27001:2022 clause 6.1.2, iso.org/obp · verified 2026-09-03
- 2ISO/IEC 27001:2022 clause 6.1.3, iso.org/obp · verified 2026-09-03
- 3ISO/IEC 27001:2022 clause 9.1, iso.org/obp · verified 2026-09-03
- 4ISO/IEC 27001:2022 clause 9.3.2, iso.org/obp · verified 2026-09-03
- 5ISO/IEC 27001:2022 clause 9.3.3, iso.org/obp · verified 2026-09-03
- 6ISO/IEC 27001:2022 clause 10.2, iso.org/obp · verified 2026-09-03
- 7ISO/IEC 27001:2022 contents, iso.org/obp · verified 2026-09-03