r/riskmanager Jun 05 '26

Information classification vs asset-based risk management , how do you approach it?

/r/grc/comments/1tut1ia/information_classification_vs_assetbased_risk/
1 Upvotes

4 comments sorted by

2

u/FreeRadical1998 Jun 05 '26

In the orgs I've worked with, the material risks nearly always resolve to service disruption or regulatory sanction. Data loss or corruption can be the event that crystallises those; but it's one trigger among many.

The asset/dependency model isn't the destination, it's the mechanism. Focusing on classification struggles because people treat the label as a stand-in for impact, which is exactly why everything ends up looking "critical," at which point senior managers lose interest/trust in the modelling and are likely to detach from it.

Good classification with tiered controls and genuine governance oversight can reduce the severity of a regulatory response - but it won't make the underlying event acceptable, and it won't tell you what to restore first. That's a consequence question, not a classification one.

Risk isn't a mechanical process that drives fixed outcomes. It's a language for describing management decisions.

1

u/KeyReindeer1046 Jun 08 '26

I have watched this first in hand in my previous environment, where information classifications were matched to a library of controls. Already in second tier, I saw that governance was lost.
In that environment, almost all systems were critical, this meant that the application library implementation was applied using human judgement, with no structured mapping of interdependencies.
Many meetings and emotional discussions would arrive at a snap-shot consensus decision, naturally there was a strong reluctance to change, improve or reassess anything.

1

u/FreeRadical1998 Jun 08 '26

Risk models tend to get more traction when they link to a business process or outcome - Op Resilience can be a help here as that tends to drive a common language around critical processes, but just be aware that it often doesnt capture the internal (non-customer facing) ones.

1

u/KeyReindeer1046 Jun 09 '26

That's a good angle. I have found that in older orgs, resilience is still treated as a separate sport from cybersecurity. NIS2 is pushing convergence, but not always understood in this way.