E016 Risk Management and Information Technology is listed under banner number ITEC 5500 and is worth 3 competency units. It approaches risk from a management perspective: protecting sensitive data, intellectual property and digital assets through governance structures and a coherent mitigation strategy. E016 and ITEC 5500 are one requirement. The framing to hold throughout is that risk management is a decision process, and its output is decisions rather than a document.
Four responses, and three of them are not controls
Students arrive assuming risk management means adding protections. There are four legitimate responses and only one of them is that. You can avoid a risk by not doing the thing that creates it. You can transfer it, through insurance or contract, so someone else bears the loss. You can mitigate it with controls that reduce likelihood or impact. Or you can accept it deliberately, with a named owner, because the cost of doing otherwise exceeds the exposure. A submission that treats every risk as requiring a control has used a quarter of the available thinking.
Intellectual property gets specific attention in this course and is worth understanding as a distinct asset class. It is frequently the most valuable thing an organization holds, it is protected by legal instruments as much as by technical ones, and its exposure is often through people and suppliers rather than through systems. A risk analysis that treats source code, designs and customer lists purely as files has missed how they actually leave.
Quantification is where graduate work distinguishes itself. Qualitative ratings are quick and comparable within a register, and they hide the arithmetic that would let a manager weigh a control against a risk. Even a rough expected loss calculation, with its assumptions stated, converts a discussion about whether something feels risky into a comparison a decision maker can act on.
Governance ties it together. Who owns the register, who may accept risk at what level, how new risks enter and how often the register is reviewed are what stop risk management from becoming an annual document nobody consults.
Work here returns Competent or Not Competent, and neither letter grades nor an ordinary grade point average are recorded, leaving 3 competency units as the only size figure attached to a flat-rate six month term.
Turning aspects into a risk document
If your version of E016 uses a performance assessment, the aspects usually cover identification, analysis, response and governance. WGU requires a score of 2 in each aspect for a task to pass and judges each aspect alone, so a thorough register will not carry an unaddressed governance or monitoring aspect.
Budget before drafting. Take a rubric with six scored aspects and a target near 2,100 words. Reserve 150 words for the organization and its assets, and 110 for the close, leaving 1,840 across six aspects, or roughly 306 each. Weight by demand: two aspects requiring analysis and strategy take 420 each, which is 840; the four remaining aspects, covering identification, response selection, governance and monitoring, take 250 each, which is 1,000. Together that is 1,840.
Use all four response types across your register rather than defaulting to mitigation. A register where one risk is avoided, one transferred, several mitigated and one accepted with a named owner demonstrates the full method and reads as considered rather than reflexive.
Reserve budget for the asset inventory. Risk is always risk to something, and a document that identifies risks without first establishing what is worth protecting has skipped the step that makes prioritisation possible.
Shape for an IT risk management document
E016 deliverables usually assess risk and propose a strategy. These proportions fit that document.
| Section | Content | Share |
|---|---|---|
| Organization and assets | What the business does and what it holds: data, intellectual property, systems and their value. | 14 percent |
| Risk identification | How risks were found, and the risks themselves stated as event, cause and consequence. | 17 percent |
| Analysis | Likelihood and impact with a stated basis, and expected loss where it can be estimated. | 19 percent |
| Response strategy | Avoid, transfer, mitigate or accept for each risk, with the reasoning and cost of each choice. | 21 percent |
| Governance | Register ownership, acceptance authority by level, entry process and review cadence. | 15 percent |
| Monitoring | Indicators that a risk is materialising and what each one would trigger. | 9 percent |
| Close | Residual risk position and the single change that most reduces exposure. | 5 percent |
Sourcing risk claims
Risk management process and terminology belong to published standards on risk management and to recognised frameworks, cited by revision. Terminology precision matters here because risk, threat, vulnerability, issue and impact are all defined terms that everyday speech uses interchangeably.
Likelihood estimates need a stated basis. Historical incident data from the organization is best, industry frequency data with a year is next, and structured expert judgement is legitimate when labelled as such. What does not work is a probability that appears with no origin, because the entire analysis rests on it.
Intellectual property claims have a legal dimension, so where you assert that something is protected, cite the relevant protection rather than assuming. What is protected by copyright, what requires registration and what is only protected as a trade secret while it stays secret are different positions with different implications for how you manage the risk.
Where you propose transfer through insurance or contract, be specific about what is actually transferred. Insurance transfers financial loss and not regulatory obligation or reputational damage, and contracts transfer liability only to the extent the counterparty can pay. Noting those limits is a graduate-level observation.
Use the citation style your task names and reference inline rather than in a closing pile. That table is the document's spine and is where several aspects are scored at once.
Competent risk work and returned work
Competent submissions inventory assets before identifying risks, state a basis for every rating, use all four response types where appropriate, name an owner for every accepted risk, and describe governance that would keep the register alive.
Returns follow four shapes. Every risk is mitigated, showing no use of the other responses. Ratings appear with no basis, so the prioritisation cannot be evaluated. Accepted risks have no owner. Or the document is a register with no governance around it, which means nothing happens after it is written.
Risk appetite is the concept that turns a register into a strategy, and it is frequently missing. An organization that has not said how much risk it is willing to carry cannot decide anything consistently, because every individual decision gets argued from scratch. Proposing an appetite statement, even a simple one that sets different tolerances for regulatory, financial and reputational exposure, gives every acceptance decision in your register a reference point and demonstrates that you understand what governance is actually for.
A useful check: for each risk, confirm you have written an event, a cause and a consequence rather than a single noun. "Data breach" is a topic; "customer records exposed because a third-party integration uses a shared credential, resulting in notification obligations and contractual penalties" is a risk that can be analysed.
Performance assessment work can be revised and resubmitted with no grade penalty, so completeness beats polish when you are deciding whether to submit, because feedback is more precise than your own second guessing. If your section also carries an objective assessment, WGU objective assessments are proctored and our boundary is fixed: preparation only, with framework drills, register practice and a candid read on your preassessment result. We do not sit exams for anyone, do not assist while it is running, and portal sign-in details stay with you at all times.
Register full of mitigations only?
Send the E016 rubric and scenario. We rebuild the register with all four responses, a stated basis per rating and governance around it.
Eight mistakes that cost time in E016
- Mitigating everything. Avoid, transfer, mitigate and accept are four responses. Using one is using a quarter of the method.
- Risks written as nouns. Event, cause and consequence. A topic cannot be analysed or owned.
- Ratings with no basis. Say where the likelihood came from, even if the answer is structured judgement.
- No asset inventory. Risk is risk to something. Establish what is worth protecting before listing threats.
- Accepted risks with no owner. Acceptance requires a person with the authority to accept.
- Overstating transfer. Insurance moves financial loss, not obligation or reputation. Say what remains.
- Intellectual property as files. It leaves through people and suppliers as often as through systems.
- Register with no governance. Ownership, authority, entry process and review cadence keep it from becoming an artifact.
- No stated appetite. Without a tolerance to measure against, every acceptance decision is argued from first principles again.
Three questions students ask about E016
Is this a cybersecurity course?
Should I use qualitative or quantitative analysis?
How many risks should the register contain?
Where E016 sits in WGU's programs
The July 2026 catalog places this code in 2 current WGU programs. Open a program page for the complete standard path and term positions. The live Degree Plan remains authoritative after transfer credit, substitutions, and mentor planning.
The assessments, one by one
The public catalog does not publish this course's PA/OA identity or task count. WGU Tutors publishes at most one PA manual per course and only from a WGU-controlled public rubric. Until that source exists, PA help begins from the student's real Course of Study and OA support remains preparation only.