This article addresses frequently asked questions on risk analysis, including why, when and who should conduct IT risk analysis. It talks about the six steps necessary to perform a risk analysis, the three deliverables on the risk analysis process, and the six most common methods of risk mitigation. The appendices list control categories for operations controls, application controls, security controls and systems controls.