Skip to content
Security Risk Templates by SRMBOK

Practical security risk guidance, worked examples and templates.

  • Articles
  • SRMBOK
  • RMBOK
  • Articles
  • SRMBOK
  • RMBOK

Category: Assess & prioritise

How Do I Set the Scope of a Security Risk Assessment?

Set the boundary before you assess: Agree the objective; Define what is in scope; Record exclusions and limits.

Set the security risk assessment scope properly, with boundaries, dates and assumptions fixed up front, plus a free scoping statement template.

How Do I Turn a Risk Register into Better Decisions?

Turn a risk entry into a decision: Describe the scenario; Test the controls; Choose and own the action.

What is RMBOK? A practitioner’s introduction to writing risk statements, running bow-tie analysis and testing controls that actually work.

How Do I Carry Out a Security Risk Assessment?

Move from purpose to practical action: Set scope and context; Assess the risks; Treat, monitor and review.

Work through a security risk assessment: agree scope, identify scenarios, assess controls and risk, choose treatments and review. Includes a practical flowchart.

How Do I Use Bow-Tie Analysis to Understand a Security Risk?

Trace the path from cause to harm: Threats; Top event; Consequences.

Bow-tie analysis explained simply: focal events, causes, consequences and controls, with a worked example, in about the time it takes to read this.

How Do I Apply ISO 31000 Without Adding Unnecessary Paperwork?

Make the risk process support decisions: Clarify context and criteria; Assess and treat risk; Monitor, review and communicate.

ISO 31000 explained in plain language: the principles, framework and full process, from setting the context through to risk treatment and review.

How Do I Run a Bow-Tie Workshop That Produces Useful Actions?

End the workshop with owned actions: Agree a precise top event; Test the control logic; Assign actions and reviews.

Twelve specific bow-tie workshop mistakes, from vague focal events to unchallenged barriers, with fixes and a facilitator’s review checklist.

How Do I Keep a Security Risk Assessment Team Working to the Same Process?

Keep the team on the same process: Make the current stage visible; Show the next decision; Revisit earlier assumptions.

A free security risk management wall chart set to keep your project room aligned on what stage the work is at, who leads it, and what happens next.

How Can Practitioners Assess Danger While Accounts Are Disputed?

Keep danger, evidence and action visible: Use the specialist framework; Record facts and uncertainty; Follow required response pathways.

How practitioners can organise uncertainty, record safety actions and seek specialist input while disputed accounts remain unresolved. A supplementary risk lens.

How Do I Stop a Security Risk Assessment Growing Beyond Its Scope?

Handle new work through scope control: Compare it with the brief; Record the proposed change; Agree effects on time and outputs.

Five scoping statement clauses that stop security risk assessment scope creep before it starts, with a worked before-and-after example and template.

How Do I Explain Risk Management to Colleagues Who See Only Paperwork?

Explain risk through a real decision: What could happen?; What changes the likelihood or harm?; What should we do next?.

Risk management is not paperwork: how to explain that to sceptical colleagues using clear risk statements and bow-tie thinking instead of forms.

Security Risk Templates by SRMBOK

Practical security risk guidance, worked examples and templates.

  • About
  • Privacy

All rights reserved