A risk model is the method an organization uses to identify its assets, the threats that affect them, how likely they are and the impact they would have, so it can decide what to protect first and how much to invest. It's the starting point of standards such as ISO 27001 and of the risk assessment an ISMS requires.
How TecnetOne handles it: Cybersecurity Consulting
risk assessment, risk management, risk analysis, risk matrix, ISO 27005