Risk Prompt Lists

Structured cue lists that help teams brainstorm where risks might come from. They highlight common sources of risk, and many industry- or project-specific versions can be found from public sources.

Key Points

  • Acts as a trigger to consider diverse sources of risk during identification.
  • Usually organized by categories (for example: technical, external, organizational, regulatory, and vendor).
  • Can be tailored to the industry, lifecycle, and complexity of the project.
  • Complements other techniques such as brainstorming, checklists, SWOT, and PESTLE.

Example

A healthcare software project uses a risk prompt list with categories like requirements, integration, cybersecurity, compliance, suppliers, and operations. During a workshop, each category is reviewed to uncover threats (e.g., new privacy regulations) and opportunities (e.g., vendor performance incentives) that are then logged for analysis.

PMP Example Question

Which tool best ensures the team considers a broad set of potential risk sources during a risk identification workshop?

  1. Risk prompt list
  2. Risk threshold
  3. Risk appetite statement
  4. Risk register

Correct Answer: A — Risk prompt list

Explanation: A risk prompt list provides categorized cues that stimulate thinking about where risks may originate. Thresholds and appetite guide risk attitude, and the register records identified risks rather than prompting them.

ICS/OT Cybersecurity Fundamentals — Security Built for Industrial Systems

Industrial control systems cannot be secured like ordinary IT. A forced reboot, aggressive scan, or incompatible patch can interrupt production and create real safety consequences. Effective OT security begins with understanding the systems, constraints, and risks unique to industrial environments.

This course gives IT professionals, engineers, operators, and security practitioners a practical foundation in ICS threats, zone and conduit design, risk assessment, passive asset visibility, and vendor evaluation. You will learn how IEC 62443, NIST CSF, and MITRE ATT&CK for ICS apply where availability and safety come first.

Eight reconstructed incidents—including Stuxnet, Triton, Ukraine 2015, Colonial Pipeline, and PIPEDREAM—show how attackers move through OT environments, what they target, and which defenses could have changed the outcome.

Watch the course preview, then build the vocabulary, frameworks, and judgment needed to take credible first steps in ICS/OT cybersecurity.

Explore the Course


ICS/OT Cybersecurity Fundamentals course preview

Build an ICS/OT cybersecurity foundation that fits the real environment

Standard IT controls can disrupt the industrial systems they are meant to protect. Learn how to assess OT risk, design zones and conduits, apply IEC 62443 security levels, use MITRE ATT&CK for ICS, and establish passive asset visibility without risking production. Eight reconstructed incidents connect attacker techniques to the controls that failed, giving you the vocabulary and judgment to make credible security decisions from day one.

Explore the Course