20 August 2026
The objective of an Information Security Risk Management Committee (ISRMC) is to provide structured oversight of cyber security and information risks that could impact operations, reputation, finances, and regulatory compliance.
Key functions of the ISRMC include -
Providing strategic direction of information and security initiatives based on overall business and technology strategy, enabling the organisation to achieve its business goals within acceptable levels of risk.
Ensuring emerging cyber security threats are identified and addressed appropriately.
Overseeing compliance activities in line with relevant laws, regulations, and standards.
Click below to see more details on key functions of the ISRMC.
The Information Security Risk Management Committee (ISRMC) and the Audit and Risk Committee (ARIC) play complementary roles within an organisation’s governance framework.
Operating at a management level the ISRMC provides detailed oversight of technology-related risks and compliance activities. The ARIC, on the other hand, provides broader oversight of organisational governance, risk management, internal controls, and assurance. It is typically a board or executive committee that requires visibility of significant risks across the enterprise, including cyber and information security threats.
The relevance of the ISRMC to the ARIC lies in the reporting and assurance relationship. The ISRMC monitors cyber risks, evaluates control effectiveness, reviews incidents, and tracks remediation activities. It then escalates material issues, emerging threats, key risk indicators, and compliance concerns to the ARIC. This enables the ARIC to fulfil its governance responsibilities and ensure that information security risks are appropriately managed and aligned with the organisation’s risk appetite.
In summary, the ISRMC provides specialist expertise and operational oversight of information security risks, while the ARIC relies on this information to exercise strategic oversight, make informed decisions, and provide assurance that cyber and information security risks are being effectively managed across the organisation.
Some key points to consider when forming your ISRMC:
Establish executive sponsorship and cross-functional membership (business, IT, risk, legal, governance and compliance).
Align security risk management with organisational objectives and priorities.
Regularly review significant risks, threats, vulnerabilities, and incidents.
Assign clear ownership and accountability for risk treatment actions.
Use consistent risk reporting and metrics to support informed decisions.
Click below to discover why AI makes cyber security risk registers more important than ever.
AI Amplifies The Importance Of A Cyber Security Risk Register
Kaon Security has helped organisations to draft their initial ISRMC charter, select committee members, set up and run their first few ISMRC meetings.
If you would like to talk to one of our consultants about the benefits of establishing an ISRMC then contact us today.