Understanding is not the same as having information - it is the process of putting that information into context to work out what it means in a particular situation. We conduct a similar process on a larger scale during the 'understand' stage of the risk management process during which we build on our knowledge of an organization to understand the risks it faces.