1. Risk management is a sequential process and based on the adage that you can't mange something you can't measure. There is no sense implementing monitoring and reporting processes for controls until you have identified your risks. You cannot effectively respond to a security event unless you have a clear understanding of your controls.
2. This is a process of continuous improvement. Controls will fail and you will need a process to not only address the reduction of immediate losses from the event, but the adjustment of controls to avoid future failures. Just as the Threats and Vulnerabilities confronting the organization are constantly evolving, the risk management process must continuously improve and adjust to address these changes.