# Risk Management Policy

> **Template — adapt before use.** Replace `[bracketed]` placeholders and have an owner approve it. Not compliance advice.

| | |
|---|---|
| **Owner** | [Role] | **Approved** | [YYYY-MM-DD] | **Review** | Annual | **Version** | 1.0 |

Maps to: ISO 27001 Clause 6 & A.5.* · SOC 2 CC3 · PCI DSS 12.3 · NIST CSF (Identify).

## 1. Purpose & scope
Defines how [Company Name] identifies, assesses, treats, and monitors information-security risk across its assets, systems, and third parties.

## 2. Methodology
- **Identify** assets and the threats and vulnerabilities affecting them.
- **Assess** each risk on **likelihood** and **impact** using a defined scale (e.g. 1–5 each → risk score = L × I).
- **Treat** each risk via one of: mitigate (apply controls), transfer (insurance/contract), avoid (stop the activity), or accept (with sign-off).
- **Monitor** residual risk and re-assess on the cadence below or after material change.

## 3. Risk scale
| Score | Rating | Action |
|---|---|---|
| 1–6 | Low | Accept or monitor |
| 7–14 | Medium | Treat within [90 days] |
| 15–25 | High | Treat within [30 days]; executive awareness |

## 4. Risk register
All risks are recorded in a risk register with: description, owner, score, treatment, status, and review date. The register is reviewed at least [quarterly].

## 5. Roles
[Role] maintains the register and methodology; asset owners assess and treat risks they own; management accepts residual risk above the defined threshold.

## 6. Cadence
Full risk assessment at least annually; targeted re-assessment on significant change (new system, incident, vendor, regulation).

## Revision history
| Version | Date | Author | Change |
|---|---|---|---|
| 1.0 | [YYYY-MM-DD] | [Name] | Initial issue |
