STEP 8: Fill-out the Security Risk Register (SRR)
The SRR is the output of the SRA process and contains the key information from steps 1-6 above. It should look like this:
Column 1: Threat Name (from step 2)
Column 2: Threat Description (from step 3)
Column 3: Vulnerability Description (from step 3)
Column 4: Existing Mitigation Measure (from step 6)
Column 5: Risk Rating (from the matrix in step 5)
Column 6: Additional Mitigation Required (from step 6)
Fill out the other parts of the SRR such as the date and names of persons who conducted the assessment. Then, submit it to your management and security for review and follow-up.
At the IFRC, the SRR must be submitted to the Senior Manager (i.e., Head of Country Office) and the Global Security Unit for review and approval.
What happens next?
The final step is taken by management and is often referred to as the “risk evaluation” step (according to ISO standards). In brief, the management team will use the information derived from the SRA (and contained in the SRR) to evaluate the risks and decide which risks need to be “treated” (reduced to an acceptable level). Decisions may include:
• Whether a risk needs treatment;
• Priorities for treatment;
• Whether an activity should be undertaken.
In terms of treatment, the IFRC Global Security Unit usually requires that measures be taken to reduce all high or extreme security risks to medium.
Risk treatment measures may include writing new (or updating) procedures and plans, investing in training and equipment, or restricting/avoiding activities or travel in some areas,
These “additional” measures are also captured in the SRR and usually assigned to a manager for implementation within a given deadline (to be recorded in columns 5-9 of the SRR).
That’s it!
We hope you found these instructions useful. We recognise that there are many good ways to conduct SRAs, but we have found that this approach works well - including in emergencies, and at the area, country and regional level.
You can send us your suggestions by clicking the button below.