What is a security risk assessment?
A security risk assessment identifies threats to an organization's systems and data, estimates their likelihood and impact, and ranks them. Results are recorded in a risk register. ISO 27001, SOC 2, and HIPAA all require periodic risk assessments.
What the buyer is really asking
Describe how you identify and rate security risks: the method, who takes part, and how often you repeat it. Annual plus on significant change is the usual expectation. Buyers may ask for the risk register itself.
Other ways buyers ask it
Every one of these wants the same answer:
- “How do you conduct risk assessments?”
- “How often do you update your risk assessment?”
- “Do you maintain a risk register?”
- “What risk assessment methodology do you follow?”
Evidence to have ready
- The risk assessment procedure
- The current risk register, redacted if needed
How Tyrvar answers this
Tyrvar treats every wording above as one question. You write the answer once, attach the evidence, and revisit it when your setup changes. Each buyer gets that approved answer no matter how their questionnaire words it. If you have not answered it yet, Tyrvar flags the question for you and does not make something up. Try it on your own questionnaire.