* [Topics](/en/topics "Topics")
* [Security](/en/topics/security "Security")
* What is risk management?
What is risk management?
========================
Published  October 11, 2019•*4*-minute read
Copy URL
Jump to section
---------------
OverviewWhat does risk management look like in action?Enterprise risk managementIT risk managementRisk management processRisk management approachesWhy choose Red Hat?
Overview
--------
Risk management is the process of identifying and assessing risks and creating a plan to minimize or control those risks and their potential impact on an organization. A risk is a potential for loss or damage. Risks can come from a variety of places such as legal liability, natural disasters, accidents, management errors, or cybersecurity threats.
What does risk management look like in action?
----------------------------------------------
It's all about following the data. Find out why in this video.
This video can't play due to privacy settings
To change your settings, select the "Cookie Preferences" link in the footer and opt in to "Advertising Cookies or try disabling adblockers."
Recommended for you
Automate security. Align ITOps.
-------------------------------
[Watch the webinar](https://www.redhat.com/en/events/webinar/automate-security-align-itops?percmp=RHCTG0250000455235)
Enterprise risk management
--------------------------
Risk management strategies are the tactics for dealing with these risks and understanding their potential consequences. These strategies should be included in a risk management plan, which is a documented process of how your organization or team will identify and address emerging risks.
Enterprise risk management is an important part of your business strategy and relationship with stakeholders, as it helps you to avoid circumstances that could keep your business from achieving its goals.
Many industries are required to follow compliance regulations as a part of business operations, and there are several organizations that have established standards for managing risk, including the [National Institute of Standards and Technology](https://www.nist.gov/) and the [International Organization for Standardization (ISO)](https://www.iso.org/home.html).
Financial services, for example, is an industry that deals with extensive compliance requirements and regulations. There is also a lot of risk involved, between keeping customer data secure, making investment decisions, and determining credit risk.
The [ISO 31000 principles](https://www.iso.org/obp/ui/#iso:std:iso:31000:ed-1:v1:en) can be used as a risk management framework for companies, regardless of industry. Risk management standards help organizations implement a risk management plan in a systematic way.
[Here are ways to simplify corporate security operations centers](/en/resources/security-automation-ebook "Simplify your security operations center")
IT risk management
------------------
For IT, risk comes from the potential for loss or damage if a threat exploits a vulnerability in your hardware or software. [Common Vulnerabilities and Exposures (CVE)](https://www-admin.corp.redhat.com/en/topics/security/what-is-cve), a list of publicly disclosed security flaws, help IT professionals coordinate their efforts to prioritize and address these vulnerabilities to make computer systems more secure.
The way we develop, deploy, integrate, and manage IT is dramatically changing. [IT security](/en/topics/security) needs to be part of the infrastructure and product lifecycle as early as possible, and integrated into your risk management strategy, so that your organization can be both proactive and reactive.
One way to approach mitigating risks is by using tools such as [predictive analytics](/en/topics/automation/how-predictive-analytics-improve-it-performance) and automation to monitor your infrastructure.
Ops teams can use predictive analytics to proactively find and address problems before they affect your environment. You can also use predictive analytics to prevent security issues and avoid unplanned downtime by looking for anything unusual on a network and identifying the root cause of potential vulnerabilities. 
[Automation](/en/topics/automation) ensures fast and effective feedback that doesn’t slow the product lifecycle down, and can also be used to remediate identified issues.
[Here's a predictive analytics tool for IT](/en/lightspeed "product | red hat insights")
Risk management process
-----------------------
It’s not possible for an organization to avoid all risk entirely, and the consequences of a risk don’t have to be negative. As a business, you will need to weigh the potential risk against the potential opportunity, and establish what an acceptable level of risk is. You can then use this information for decision making.
Risk management involves prioritizing the risks that have the highest chance of happening and would also have the greatest impact if they did occur, and dealing with these risks first through risk mitigation.
### Risk management steps:
1. **Risk identification:** Identify and describe potential risks. Types of risks could include financial risks, operational risks (such as risks to a supply chain), project risks, business risks, and market risks—among others. Identified risks should be recorded in a risk register or be documented in some way.
2. **Risk analysis:** Determine the probability of a new risk happening by analyzing the risk factors and documenting potential consequences.
3. **Risk assessment and evaluation:** Using internal audits and risk analysis, determine the magnitude of a risk. You’ll also need to decide what level of risk is acceptable, and what needs to be dealt with immediately.
4. **Risk mitigation:** Once you’ve determined the priority and importance of risks, you can proceed with a risk response strategy to minimize or control the risk.
5. **Risk monitoring:** Risks and metrics need to be continuously monitored to make sure that risk mitigation plans are working, or to keep you aware if a risk becomes a greater threat.
Risk management approaches
--------------------------
The main risk management approaches include avoidance, reduction, sharing, and retention.
* **Risk avoidance:** Risk avoidance involves stopping and avoiding any activities that could lead to a risk.
* **Risk reduction:** Risk reduction is focused on actions that will reduce the probability of a risk occurring or the impact of a risk.
* **Risk sharing:** Risk sharing is when an organization will transfer or share part of the risk with another organization. An example is outsourcing manufacturing or customer service functions to a third party.
* **Risk retention:** Risk retention occurs when risks have been evaluated and the organization decides to accept the potential risk. No action is taken to mitigate the risk, but a contingency plan may still be put in place.
Why choose Red Hat?
-------------------
Red Hat tests, hardens, and supports open source software to make it ready for the enterprise. Our goal is to help your business remain competitive, flexible, and adaptable while maintaining security and regulatory compliance.
Our solutions can help team members and risk managers set up risk remediation and prevention tactics across their environments. [Red Hat® Insights](/en/lightspeed) provides predictive analytics with comprehensive assessment and intelligent prediction across physical, virtual, container, private, and public cloud environments.
Your organization can proactively identify risks as part of your risk management strategy, and automate remediation across your Red Hat infrastructure by using [Red Hat® Ansible® Automation Platform](/en/technologies/management/ansible) Playbooks along with Insights.
Recommended for you
E-book
The cost of human error and the advantages of automation
--------------------------------------------------------
Learn about the benefits of modernizing your monolithic Java applications using cloud-native and microservice architectures and approaches.
[Read the e-book](https://www.redhat.com/en/resources/advantages-security-automation-e-book?percmp=RHCTG0250000455234)
All Red Hat product trials
--------------------------
Our no-cost product trials help you gain hands-on experience, prepare for a certification, or assess if a product is right for your organization.
[Keep reading](/en/products/trials "All Red Hat product trials")
Keep reading
------------
### What is security automation?
Security automation uses technology to perform tasks with reduced human assistance to integrate security processes, applications, and infrastructure.
[Read the article](/en/topics/automation/what-is-security-automation "article | what is security automation")
### What is SOAR?
SOAR refers to 3 key software capabilities that security teams use: case and workflow management, task automation, and a centralized means of accessing, querying, and sharing threat intelligence.
[Read the article](/en/topics/security/what-is-soar "article | what is soar")
### What's an insider threat?
An insider threat is leaked or misused data that—whether released accidentally or purposefully—could be used in malicious ways or viewed by individuals who shouldn’t have legitimate access.
[Read the article](/en/topics/security/what-are-insider-threats "article | What's an insider threat")
Security resources
------------------
### Related content
* Blog post
  [Enable intelligent insights with Red Hat Satellite MCP Server](/en/blog/enable-intelligent-insights-red-hat-satellite-mcp-server)
* E-book
  [Automation for financial services: Enhanced operations and future flexibility](/en/engage/automation-for-financial-services-ebook)
* Blog post
  [MCP security: Implementing robust authentication and authorization](/en/blog/mcp-security-implementing-robust-authentication-and-authorization)
* Overview
  [Manufacturers combine modernization and continuity with Red Hat](/en/resources/anon-manufacturing-overview)
### Related articles
* [What is patch management?](/en/topics/management/what-patch-management-and-automation)
* [What is security automation?](/en/topics/automation/what-is-security-automation)
* [What is AI security?](/en/topics/ai/what-is-ai-security)
* [Why choose Red Hat for automation?](/en/topics/automation/why-choose-red-hat-for-automation)
* [What's an insider threat?](/en/topics/security/what-are-insider-threats)
* [What is an Ansible Playbook?](/en/topics/automation/what-is-an-ansible-playbook)
* [What is SOAR?](/en/topics/security/what-is-soar)
* [How to build an IT automation strategy](/en/topics/automation/build-an-automation-strategy)
* [Learning Ansible basics](/en/topics/automation/learning-ansible-tutorial)
* [What is post-quantum cryptography?](/en/topics/security/post-quantum-cryptography)
* [What is software supply chain security?](/en/topics/security/what-is-software-supply-chain-security)
* [What is lightweight directory access protocol (LDAP) authentication?](/en/topics/security/what-is-ldap-authentication)
* [Ansible vs. Salt: What you need to know](/en/topics/automation/ansible-vs-salt)
* [Ansible vs. Chef: What you need to know](/en/topics/automation/ansible-vs-chef)
* [Ansible vs. Puppet: What you need to know](/en/topics/automation/ansible-vs-puppet)
* [Ansible vs. Terraform](/en/topics/automation/ansible-vs-terraform)
* [What is secrets management?](/en/topics/devops/what-is-secrets-management)
* [What is IT service management (ITSM)?](/en/topics/automation/what-is-it-service-management-itsm)
* [Automating Microsoft Windows with Red Hat Ansible Automation Platform](/en/technologies/management/ansible/automate-microsoft-windows-with-ansible)
* [What is confidential computing?](/en/topics/security/what-is-confidential-computing)
* [What are SPIFFE and SPIRE?](/en/topics/security/spiffe-and-spire)
* [Red Hat Enterprise Linux security](/en/technologies/linux-platforms/enterprise-linux/security)
* [What is zero trust?](/en/topics/security/what-is-zero-trust)
* [What is DevOps automation?](/en/topics/automation/what-is-devops-automation)
* [What is Infrastructure as Code (IaC)?](/en/topics/automation/what-is-infrastructure-as-code-iac)
* [Ansible vs. Kubernetes: how they work together](/en/topics/automation/Ansible-vs-Kubernetes)
* [What is a configuration management database (CMDB)?](/en/topics/automation/what-is-a-configuration-management-database-cmdb)
* [What is cloud migration? And how can automation help?](/en/topics/automation/what-is-cloud-migration)
* [Functional safety and continuous certification on Linux](/en/topics/open-source/functional-safety-and-continuous-certification-on-linux)
* [What is a software-defined data center (SDDC)?](/en/topics/automation/what-is-a-sddc)
* [What is IT automation?](/en/topics/automation/what-is-it-automation)
* [Why choose Red Hat Ansible Automation Platform as your AI foundation?](/en/topics/automation/automation-and-ai)
* [What is access control?](/en/topics/security/what-is-access-control)
* [What is virtual infrastructure management? And how can automation help?](/en/topics/automation/virtual-infrastructure-management)
* [What is IT migration?](/en/topics/automation/what-is-it-migration)
* [How to automate migrations with Red Hat Ansible Automation Platform](/en/technologies/management/ansible/automate-migrations-with-red-hat-ansible-automation-platform)
* [Why use Red Hat Ansible Automation Platform with Red Hat OpenShift?](/en/technologies/cloud-computing/openshift/ansible-on-openshift)
* [What is a CVE?](/en/topics/security/what-is-cve)
* [What is CloudOps?](/en/topics/automation/what-is-cloudops)
* [Red Hat Satellite on Red Hat Enterprise Linux](/en/technologies/management/satellite/satellite-for-rhel)
* [What is role-based access control (RBAC)?](/en/topics/security/what-is-role-based-access-control)
* [What is kubernetes security?](/en/topics/containers/kubernetes-security)
* [Which Red Hat Ansible Automation Platform deployment option is right for you?](/en/technologies/management/ansible/ansible-deployment-options)
* [What is an Ansible module—and how does it work?](/en/topics/automation/what-is-an-ansible-module)
* [How to manage and automate applications at the edge](/en/topics/edge-computing/how-to-manage-automate-applications-edge)
* [How to build an automation Center of Excellence](/en/topics/automation/how-to-build-automation-center-of-excellence)
* [Shift left vs. shift right](/en/topics/devops/shift-left-vs-shift-right)
* [What is orchestration?](/en/topics/automation/what-is-orchestration)
* [How to adopt Automation as Code: Extending Infrastructure as Code into Policy as Code](/en/topics/automation/how-to-adopt-automation-as-code)
* [What is a webhook?](/en/topics/automation/what-is-a-webhook)
* [Red Hat Lightspeed data and application security](/en/topics/management/data-application-security)
* [What is an Ansible Role—and how is it used?](/en/topics/automation/what-is-an-ansible-role)
* [What is CI/CD security?](/en/topics/security/what-is-cicd-security)
* [What is an intrusion detection and prevention system (IDPS)?](/en/topics/security/what-is-an-IDPS)
* [What is security information and event management (SIEM)?](/en/topics/security/what-is-SIEM)
* [What is data management?](/en/topics/data-services/what-is-data-management)
* [The increasing importance of cybersecurity in banking](/en/topics/financial-services/increasing-importance-cybersecurity-banking)
* [Gain security with Red Hat Ansible Automation Platform](/en/technologies/management/ansible/gain-security-with-red-hat-ansible-automation-platform)
* [What is NetOps?](/en/topics/automation/what-is-netops)
* [What is an Ansible Rulebook?](/en/topics/automation/what-is-an-ansible-rulebook)
* [What is edge security?](/en/topics/security/what-is-edge-security)
* [What is configuration management](/en/topics/automation/what-is-configuration-management)
* [What is event-driven automation?](/en/topics/automation/what-is-event-driven-automation)
* [Zero-Touch Provisioning and telco automation with Red Hat](/en/topics/telecommunications/zero-touch-provisioning-and-telco-automation-at-red-hat)
* [What is the importance of operational resilience?](/en/topics/financial-services/what-is-operational-resilience)
* [What is vulnerability management?](/en/topics/security/what-is-vulnerability-management)
* [What is backup and recovery?](/en/topics/security/backup-and-recovery)
* [What is container security?](/en/topics/security/container-security)
* [What is infrastructure automation?](/en/topics/automation/what-is-infrastructure-automation)
* [What is DevSecOps?](/en/topics/devops/what-is-devsecops)
* [What is YAML?](/en/topics/automation/what-is-yaml)
* [What is provisioning?](/en/topics/automation/what-is-provisioning)
* [What is compliance management?](/en/topics/management/what-is-compliance-management)
* [Understanding Ansible, Terraform, Puppet, Chef, and Salt](/en/topics/automation/understanding-ansible-vs-terraform-puppet-chef-and-salt)
* [Why choose Red Hat for DevSecOps](/en/topics/devops/why-choose-red-hat-for-devsecops)
* [What is cloud orchestration?](/en/topics/automation/what-is-cloud-orchestration)
* [What is cloud governance?](/en/topics/automation/what-is-cloud-governance)
* [What is a configuration file?](/en/topics/linux/what-configuration-file)
* [Security in the software development lifecycle](/en/topics/security/software-development-lifecycle-security)
* [Ansible vs. Red Hat Ansible Automation Platform](/en/technologies/management/ansible/ansible-vs-red-hat-ansible-automation-platform)
* [What is cloud automation?](/en/topics/automation/what-is-cloud-automation)
* [What is network automation?](/en/topics/automation/what-is-network-automation)
* [What are managed IT services?](/en/topics/cloud-computing/what-are-managed-it-services)
* [Kubernetes security best practices](/en/topics/containers/kubernetes-security-best-practices)
* [What is business process management?](/en/topics/automation/what-is-business-process-management)
* [What is the Red Hat Ansible Automation Platform automation controller?](/en/technologies/management/ansible/automation-controller-product-feature)
* [Security for IoT devices](/en/topics/security/security-for-iot-devices)
* [What is identity and access management (IAM)?](/en/topics/security/what-identity-and-access-management-iam)
* [What is business process automation?](/en/topics/automation/what-is-business-process-automation)
* [Advantages of Kubernetes-native security](/en/topics/containers/advantages-of-kubernetes-native-security)
* [Intro to Kubernetes security](/en/topics/containers/intro-kubernetes-security)
* [Container and Kubernetes compliance considerations](/en/topics/containers/compliance)
* [What is IT process automation?](/en/topics/automation/what-is-it-process-automation)
* [What is deployment automation?](/en/topics/automation/what-is-deployment-automation)
* [What is business optimization?](/en/topics/automation/business-optimization)
* [What is Kubernetes cluster management?](/en/topics/containers/what-is-kubernetes-cluster-management)
* [What is SRE?](/en/topics/devops/what-is-sre)
* [What is SELinux?](/en/topics/linux/what-is-selinux)
* [Hybrid cloud security](/en/topics/security/what-is-hybrid-cloud-security)
* [What is an SOE?](/en/topics/management/what-is-an-soe)
* [What is IT system life-cycle management?](/en/topics/management/it-system-life-cycle-management)
* [What is API security?](/en/topics/security/api-security)
* [What is robotic process automation (RPA?)](/en/topics/automation/what-is-robotic-process-automation)
* [What is network management?](/en/topics/management/what-is-network-management)
* [What is financial services security (and compliance)?](/en/topics/security/security-and-compliance-financial-services)
* [What is malware?](/en/topics/security/what-is-malware)
* [What is cloud security](/en/topics/security/cloud-security)
* [What is cloud management?](/en/topics/cloud-computing/what-is-cloud-management)
* [What's business automation?](/en/topics/automation/whats-business-automation)
[More about this topic](/en/topics/security "More about this topic")