A central record of current risks, and related information, for a given scope or organization. Current risks are comprised of both accepted risks and risk that are have a planned mitigation path (i.e., risks to-be-eliminated as annotated in a POA&M). See OMB Circular A-11 for detailed information about risk register contents for Federal entities.
Source(s):
NISTIR 8170
A repository of risk information including the data understood about risks over time.
Source(s):
NISTIR 8286
from
OMB Circular A-11