Risk management is a sequential process and based on the adage that you can't mange something you can't measure. There is no sense implementing monitoring and reporting processes for controls until you have identified your risks. You cannot effectively respond to a security event unless you have a clear understanding of your controls.