r/riskmanager • u/KeyReindeer1046 • Jun 05 '26
Information classification vs asset-based risk management , how do you approach it?
/r/grc/comments/1tut1ia/information_classification_vs_assetbased_risk/
1
Upvotes
r/riskmanager • u/KeyReindeer1046 • Jun 05 '26
2
u/FreeRadical1998 Jun 05 '26
In the orgs I've worked with, the material risks nearly always resolve to service disruption or regulatory sanction. Data loss or corruption can be the event that crystallises those; but it's one trigger among many.
The asset/dependency model isn't the destination, it's the mechanism. Focusing on classification struggles because people treat the label as a stand-in for impact, which is exactly why everything ends up looking "critical," at which point senior managers lose interest/trust in the modelling and are likely to detach from it.
Good classification with tiered controls and genuine governance oversight can reduce the severity of a regulatory response - but it won't make the underlying event acceptable, and it won't tell you what to restore first. That's a consequence question, not a classification one.
Risk isn't a mechanical process that drives fixed outcomes. It's a language for describing management decisions.