Write a concrete scenario
Instead of saying 'email is risky,' describe an event: an unauthorized person accesses a shared mailbox and reads private requests. Identify the information or service affected, the conditions that make the event possible, and the likely consequences.
Connect controls to the scenario
Individual accounts, restricted permissions, additional authentication, and access reviews may reduce different parts of the risk. A control can prevent an event, help detect it, or support recovery. Explain which role a proposed measure serves rather than treating every measure as interchangeable.
Recognize remaining risk
Controls have limits. A team might reduce exposure while still accepting a defined level of remaining risk. That decision needs an appropriate owner, a reason, and a review point. A beginner exercise can use qualitative labels such as low, medium, and high without pretending they are precise measurements.
- State assumptions explicitly.
- Assign responsibility for reviewing the decision.
- Revisit the assessment when the system or data changes.