RISKORIA ADVISING & PROFESSIONAL SERVICES D.O.O. · ZAGREB+385 97 737 1345INFO@RISKORIA.EU

Risk management

A risk register is not a table written once a year for the auditor. We build an assessment the board understands and actually decides by.

LEGAL FRAMEWORKREGULATION NN 135/2024, ANNEX IIZKS NN 14/2024ISO/IEC 27001:2022

Why this is the foundational measure

Risk management is the third measure of Annex II, and the way into almost all the others.

The risk assessment is what decides which controls you apply at all and how deeply. That is why an auditor almost always starts from the risk register: if it does not exist, or does not match the real business, the other measures are left without a rationale. The Regulation says as much, since sub-measure 3.3 requires a response proportionate to the level and criticality of the risk.

The level of implementation, basic, medium or advanced, is not yours to choose. It is set by the national risk assessment during categorisation, under Article 38 of the Regulation, and does not depend on whether you are an essential or an important entity. The deadline for implementing the mandatory measures is twelve months from delivery of the categorisation notice, under Article 26(5) of the Act.

We work to the NCSC-HR guidance issued under Article 45(3) of the Regulation, with ISO/IEC 27005:2022 as the reference framework. The result is documentation that satisfies an auditor, but above all an assessment the management body can actually decide on.

The process, step by step

Eight steps following the four segments of the NCSC-HR guidance: context, assessment, treatment and periodic updating. Each step lists what it leaves behind as a record.

01

Establishing the context

We set the scope: which business processes are in, which information assets carry them, and which legal, contractual and regulatory obligations apply to you. This is also where the criteria for assessing and accepting risk are set, because without them there is no way to say later whether a risk is acceptable.

SCOPEPROCESS LISTACCEPTANCE CRITERIA
02

Critical asset inventory

A risk register without an asset register is guesswork. We list software and hardware assets with an identifier, a location and an owner, and separately identify which data is critical. That is measure 2 of Annex II, but without it a risk assessment has nothing to stand on.

ASSET INVENTORYCRITICAL DATA LISTASSET OWNERS
03

Appointing risk owners

The risk owner is the person who can decide about the risk, that is the process manager or a board member, not the IT administrator. Alongside them the NCSC-HR guidance recognises a delegated manager, who handles the risk operationally, and a security adviser, who advises the owner. IT implements the control, but the risk is accepted by whoever answers for the business.

APPOINTMENT DECISIONRESPONSIBILITY DESCRIPTION
04

Identifying threats and vulnerabilities

A threat is a possible cause of an unwanted event; a vulnerability is the weakness that threat can exploit. We start from the threat and vulnerability catalogue in the NCSC-HR guidance, but tie every threat to your process and your assets, because an unconnected list is worth nothing in an audit.

THREAT CATALOGUEVULNERABILITY CATALOGUELINK TO ASSETS
05

Analysis and evaluation

We assign a likelihood and an impact to each risk and compare the result against the acceptance criteria. We work qualitatively, through a matrix, and for critical assets quantitatively as well, through expected loss. The NCSC-HR guidance recommends a combined approach for most entities, and in practice that is what gives the management body the most convincing picture.

RISK MATRIXEXPECTED LOSS CALCULATIONACCEPTABILITY RATING
06

Risk treatment plan

For every unacceptable risk one of four strategies is chosen: reduce it through controls, avoid it by dropping the activity, transfer it through insurance or contract, or knowingly accept it. Each decision gets an owner, a deadline and a residual risk. The chosen controls come from Annex II of the Regulation, so the treatment plan is what determines which controls from the other twelve measures apply at all.

TREATMENT PLANSTRATEGY PER RISKRESIDUAL RISKSTATEMENT OF APPLICABILITY
07

Register and reporting

The risk register holds the description of the risk, the assessment of likelihood and impact, the current status and the measures taken. The report to the management body is written in the language of decisions, not of tools: what can happen, what it would cost and what we are asking to have approved. Sub-measure 3.4 requires reporting to be regular and to reach the parts of the business that decide.

RISK REGISTERREPORT TO MANAGEMENTMINUTES OF THE MEETING
08

Annual review cycle

Sub-measure 3.1 requires the process to be updated annually. On top of that the register is reviewed after every significant incident, every major system change and every new supplier with access. The review has to leave a dated record, because an audit does not prove intent, it follows the trail.

REVIEW RECORDDATE AND PARTICIPANTSLIST OF CHANGES

Matrix and calculation

Qualitative assessment through the matrix, quantitative through expected loss. The guidance recommends combining the two.

LOW IMPACTMEDIUM IMPACTHIGH IMPACTHIGH LIKELIHOODMediumHighCriticalMEDIUM LIKELIHOODLowMediumHighLOW LIKELIHOODLowLowMedium

The three by three matrix is the one shown in the NCSC-HR guidance. An entity may use a finer scale, five by five for example, if that suits it better. What cannot be skipped are written acceptance criteria and the management body’s confirmation that it accepts them.

SLE = AV × EFSingle loss expectancy. Asset value multiplied by the exposure factor, that is the share of the asset lost when the event occurs.
ALE = SLE × AROAnnualised loss expectancy. Loss per event multiplied by the expected number of such events in a year.

An example: a server worth 40,000 euros, an exposure factor of 0.5 and one such event every two years give a single loss expectancy of 20,000 euros and an annualised loss expectancy of 10,000 euros. The figure is not a prediction but a yardstick against the cost of the control.

Threat and vulnerability catalogue

The NCSC-HR guidance lists 45 typical threats and 78 typical vulnerabilities, each in seven groups. The catalogue is a starting point, not a finished document.

THREATS, 45 IN SEVEN GROUPS

GROUPEXAMPLES
Physical threatsFire, flood, earthquake, power cut
Natural hazardsStorm, extreme temperatures, epidemic
Loss of infrastructureEquipment failure, loss of connectivity, power loss
Radiation and electromagnetic interferenceInterference, electromagnetic pulse
Compromise of informationUnauthorised access, data leakage, interception, identity theft
Technical threatsMalicious code, denial of service, misuse of privileges
Human threatsSocial engineering, insider threat, user error

VULNERABILITIES, 78 IN SEVEN GROUPS

GROUPEXAMPLES
HardwarePoor maintenance, sensitivity to dust and damp, lack of redundancy
SoftwareUnpatched systems, known vulnerabilities, poor configuration
NetworkUnprotected communications, insecure protocols, no segmentation
PersonnelLack of training, weak security awareness, no vetting
LocationWeak physical protection, no access control
OrganisationMissing policies, unclear responsibilities, poor change management
Legal and regulatoryNon-compliance with regulations, deficient supplier contracts

The eight sub-measures of measure 3

Obligation marks by level, and the controls from the ZSIS control catalogue the auditor checks alongside each sub-measure.

IDSUB-MEASUREBASMEDADVCONTROLS
3.1Risk management process, documented and updated annuallyBASAMEDAADVAPOL-006
3.2Risk assessment of critical assets on an all hazards basisBASAMEDAADVAINV-004, RIZ-001, RIZ-002, RIZ-003
3.3Documenting risks and a proportionate response to eachBASAMEDAADVARIZ-004, RIZ-005
3.4Analysis and assessment methods, and regular risk reportingBASAMEDAADVARIZ-006, RIZ-007
3.5Register of identified risks, kept up to dateBASAMEDAADVARIZ-009
3.6Risk assessment before introducing solutions that increase exposureBASCMEDAADVARIZ-004, RIZ-007, RIZ-010
3.7Software tools for risk assessment and monitoringBASCMEDCADVCRIZ-011
3.8Integration into enterprise risk managementBASBMEDBADVBRIZ-012

A is a binding sub-measure at that level, B is binding subject to a condition, C is voluntary. The BAS, MED and ADV columns are the basic, medium and advanced levels. Sub-measure 3.8 is binding for an entity that already runs enterprise risk management; in that case sub-measures 3.1 to 3.7 are carried out inside that framework, and if no such framework exists, measure 3 is established as a new business process.

The full list of thirteen measures and 99 sub-measures is on the Thirteen measures page.

How this is scored

Because of the way scoring works, one weak control fails the whole sub-measure, whatever the average.

Every control receives two marks from 1 to 5: one for documentation, one for implementation. A sub-measure passes only if both conditions hold, that is if each individual control reaches its own threshold and the average of all controls reaches the sub-measure’s overall threshold.

Take sub-measure 3.2, the risk assessment of critical assets. At the basic level the individual thresholds are 3 for INV-004 and 2 each for RIZ-001, RIZ-002 and RIZ-003, with a strict overall threshold above 2.5, so an average of exactly 2.50 does not pass. At the medium level 3 is required for INV-004 and RIZ-003 and 4 for RIZ-001 and RIZ-002, with an overall threshold of 3.5. At the advanced level every control requires 4, with an overall threshold of 4.0.

Some sub-measures use a strict overall threshold, where an average equal to the threshold does not pass. The value and the operator are always read from the specific table in Annex B, never assumed.

What an auditor asks for as evidence

The list we work through ourselves in an internal readiness check. If this exists and carries a date, measure 3 is covered.

  • Cyber security risk management policy or process, with a date of approval
  • Critical asset inventory and list of critical data
  • Risk assessment methodology with acceptance criteria
  • Risk register with likelihood, impact, status and owner
  • Risk treatment plan with the chosen strategy, deadline and residual risk
  • Statement of applicability with reasons for inclusion and exclusion of controls
  • Records of regular risk reporting to the relevant parts of the business
  • Minutes of the management body meeting where risks were accepted or rejected
  • Record of the annual review of the assessment, with date and participants
  • Records of ad hoc reviews after an incident or a major change
  • Risk assessment carried out before introducing a new solution, where applicable
  • Evidence of the link to enterprise risk management, if such a process exists

Frequently asked questions

The questions most often asked before an assessment starts.

How many risks are enough?

Thirty risks that someone actually tracks beat three hundred in a table nobody opens. The Regulation does not set a number; it requires the assessment to cover critical assets and all types of threat, and every risk to have an owner and a response.

What is the difference between an asset register and a risk register?

The asset register says what you have, the risk register what can happen to it. Without the first the second is guesswork, so they always come in that order. The critical asset inventory is required by sub-measure 2.2 and the risk register by sub-measure 3.5.

What if we already run enterprise risk management?

Then sub-measure 3.8 is binding, and sub-measures 3.1 to 3.7 are carried out inside that existing framework rather than as a separate system. If you have no such framework, measure 3 is established as a new business process.

By when do we have to be ready?

The deadline for implementing the mandatory measures is twelve months from delivery of the categorisation notice, under Article 26(5) of the Act. After that, essential entities have an audit at least once every two years and important entities a self-assessment at the same interval.

Where to go next

Risk is the input; the other measures are what comes out of it.

Let us build a risk register that gets used.

Half an hour, no obligation. We look at what is in your register today, how much of it anyone actually tracks, and what is missing for measure 3 to pass.

Book a callINFO@RISKORIA.EU · +385 97 737 1345