This document discusses implementing a formal information security risk assessment. It begins by establishing context and discussing risk assessments in the Indian context. It then presents a case study of a risk assessment conducted for card data at a bank. The document outlines common challenges encountered with risk assessments and suggested solutions. It stresses the need for continuous risk assessments in Indian organizations and keys to a successful risk management program.