Security compliance and risk management assess which security threats a specific organisation actually faces, how severe each one would genuinely be if it happened, and which regulatory standards it's legally required to meet, all before any specific technical defence actually gets built. That assessment work is exactly what decides where a limited security budget and team's actual effort gets spent, since no real organisation can fully defend against every conceivable threat at once, and something has to determine which threats get prioritised.
Risk assessment prioritises limited security effort against realistic threats
Risk assessment identifies possible threats, estimates both how likely each one genuinely is and how damaging it would actually be if it happened, and uses that combined estimate to decide which risks are worth actively spending limited security resources to reduce, versus which ones get accepted as a reasonable cost of doing business. That prioritisation step is what turns an unmanageable, unlimited list of theoretical threats into a practical, actually workable security plan.
Compliance layers legally mandatory requirements on top of that internal assessment
Specific regulatory frameworks, data protection law, industry-specific security standards, impose their own required security controls regardless of what an organisation's own internal risk assessment might have independently concluded. Meeting those requirements is often a legal obligation rather than an optional judgement call, even in cases where an organisation's own genuine risk assessment might have prioritised its limited resources somewhat differently if left entirely to its own judgment.
What we're still unsure about
That risk assessment prioritises limited security effort, and that compliance imposes separate, often legally mandatory requirements on top of it, is well established, uncontroversial security practice. What's more genuinely a persistent, documented tension in the field is that meeting a compliance standard's specific checklist requirements doesn't automatically mean an organisation is actually well defended against its real, most likely threats, an organisation can be fully compliant on paper while still carrying serious, unaddressed security risk, and security professionals continue to actively debate how much weight compliance checklists should get relative to a genuinely independent risk assessment.
This sits inside Security Compliance & Risk Management, one of seven topics in Cybersecurity, one of seven domains in Computer Science, one of seventeen subjects the app can quiz you on.