Risk Categorization

Systematically grouping identified risks by where they come from (e.g., via an RBS), what part of the project they could impact (e.g., via the WBS), or another meaningful grouping such as project phase, to reveal which areas carry the greatest exposure to uncertainty.

Key Points

  • Organizes risks by source (RBS), affected work/deliverables (WBS), phase, or other taxonomy to expose hotspots.
  • Directs attention, ownership, and responses to categories with the highest concentration of risk.
  • Defined in the risk management plan and applied consistently across the risk register.
  • Supports reporting with heat maps, Pareto by category, and trend analysis over time.

Example

After risk identification, the team tags each risk with RBS (technical, external, organizational), WBS element (Subsystem 1.2, Procurement Package P-03), and project phase (design, build, test). A category report shows most threats cluster in supplier-related items and the test phase, so the manager assigns a supplier risk owner and strengthens test contingency plans.

PMP Example Question

A project manager wants to find which parts of the project face the most uncertainty. What should they do first?

  1. Perform risk categorization using RBS/WBS or phase labels to group identified risks.
  2. Calculate contingency reserves using a quantitative schedule risk analysis.
  3. Apply a probability-impact matrix to rank individual risks only.
  4. Escalate all external risks to the program manager.

Correct Answer: A — Group risks into categories by source or affected area

Explanation: Risk categorization organizes risks by source, WBS element, or phase to highlight hotspots and guide targeted responses.

ICS/OT Cybersecurity Fundamentals — Security Built for Industrial Systems

Industrial control systems cannot be secured like ordinary IT. A forced reboot, aggressive scan, or incompatible patch can interrupt production and create real safety consequences. Effective OT security begins with understanding the systems, constraints, and risks unique to industrial environments.

This course gives IT professionals, engineers, operators, and security practitioners a practical foundation in ICS threats, zone and conduit design, risk assessment, passive asset visibility, and vendor evaluation. You will learn how IEC 62443, NIST CSF, and MITRE ATT&CK for ICS apply where availability and safety come first.

Eight reconstructed incidents—including Stuxnet, Triton, Ukraine 2015, Colonial Pipeline, and PIPEDREAM—show how attackers move through OT environments, what they target, and which defenses could have changed the outcome.

Watch the course preview, then build the vocabulary, frameworks, and judgment needed to take credible first steps in ICS/OT cybersecurity.

Explore the Course


ICS/OT Cybersecurity Fundamentals course preview

Become an AI-First Agile Leader!

HK School of Management empowers you to master AI as your most powerful co-pilot—without the complexity. Transform your agile leadership with practical, prompt-based workflows and proven strategies designed for real-world scrum challenges. For the price of lunch, you get the tools to automate mundane tasks, refine backlogs with precision, and drive unprecedented efficiency in your team. Backed by our 30-day money-back guarantee—zero risk, real impact.

Learn More