Reporting artifact used to measure and report the level of potential, inherent, and residual risks as well as the effectiveness of controls to help the organization understand risk and make decisions that include security risks and other risks (such as operations, project delivery, and business) and that maintain or improve control effectiveness.