Risk Register

A centralized document or database that captures and maintains all outputs produced by the project's risk management processes.

Key Points

  • Stores details for each risk: description, cause, triggers, probability, impact, owner, response strategy, and status.
  • Living document updated across the project lifecycle; supports ongoing risk reviews and reporting.
  • Feeds planning decisions such as response plans, contingency and management reserves, and schedule/cost updates.
  • Different from the issue log and assumption log: it tracks uncertain events, not realized problems or assumptions.

Example

A construction project team maintains a risk register listing a potential permit delay (30% likelihood, high impact) with a mitigation of early submission and weekly follow-ups, owned by the permits coordinator, plus a contingency to resequence non-dependent tasks. It also records a weather-related risk with trigger conditions, planned responses (temporary covers), and current status from the latest risk review.

PMP Example Question

Which artifact primarily documents identified threats and opportunities, their analysis, owners, planned responses, and current status?

  1. Risk Register
  2. Issue Log
  3. Assumption Log
  4. Change Log

Correct Answer: A — Risk Register

Explanation: The risk register is the repository for outputs of risk management processes, including risk identification, analysis, responses, and monitoring. The other logs serve different purposes.

ICS/OT Cybersecurity Fundamentals — Security Built for Industrial Systems

Industrial control systems cannot be secured like ordinary IT. A forced reboot, aggressive scan, or incompatible patch can interrupt production and create real safety consequences. Effective OT security begins with understanding the systems, constraints, and risks unique to industrial environments.

This course gives IT professionals, engineers, operators, and security practitioners a practical foundation in ICS threats, zone and conduit design, risk assessment, passive asset visibility, and vendor evaluation. You will learn how IEC 62443, NIST CSF, and MITRE ATT&CK for ICS apply where availability and safety come first.

Eight reconstructed incidents—including Stuxnet, Triton, Ukraine 2015, Colonial Pipeline, and PIPEDREAM—show how attackers move through OT environments, what they target, and which defenses could have changed the outcome.

Watch the course preview, then build the vocabulary, frameworks, and judgment needed to take credible first steps in ICS/OT cybersecurity.

Explore the Course


ICS/OT Cybersecurity Fundamentals course preview

Advance your Lean Six Sigma expertise!

HK School of Management helps you take Lean Six Sigma to the next level without the overwhelm. Master advanced statistical tools, Excel-based analysis, and real-world improvement techniques to solve complex problems with confidence. Practical skills, tools, and guidance you can apply right away. Covered by Udemy's 30-day refund policy.

Learn More