The three steps of risk management are:
1) Risk identification: Examining security posture and risks faced by an organization.
2) Risk assessment: Documenting results of risk identification.
3) Risk control: Applying controls to reduce risks to data and information systems.
Risk identification involves identifying assets, threats, and vulnerabilities. Risk assessment assigns values and likelihoods to risks. Risk control identifies additional controls to further mitigate residual risks.