Another quick thought about risk assessment reporting
Yet another interesting risk assessment strategy is to identify a severity score for an unprotected risk, then using a matrix format, identify the interventions you’ve implemented to manage the risk and determine a score for the “protected” risk.
This works really well with security stuff because of the wide variety of interventions that can come into play (CCTV, access control, panic alarms, alarms, security presence, etc.).



