Initial risk management plans will never be perfect. Practice, experience, and actual loss results will necessitate changes in the plan and contribute information to allow possible different decisions to be made in dealing with the risks being faced.
Risk analysis results and management plans should be updated periodically. There are two primary reasons for this:
to evaluate whether the previously selected security controls are still applicable and effective, and
to evaluate the possible risk level changes in the business environment. For example, information risks are a good example of rapidly changing business environment.