|
|
Your organization should now have completed the Assessing Risk phase and
developed a prioritized list of risks to its most valuable assets. Now you must
address the most significant risks by determining appropriate actions to
mitigate them. This phase is known as Conducting Decision Support. During the
previous phase, the Security Risk Management Team identified assets, threats to
those assets, vulnerabilities that those threats could exploit to potentially
impact assets, and the controls already established to help protect the assets.
The Security Risk Management Team then created a prioritized list of risks.
The decision support process includes a formal cost-benefit analysis with
defined roles and responsibilities across organizational boundaries. The
cost-benefit analysis provides a consistent, comprehensive structure for
identifying, scoping, and selecting the most effective and cost efficient
mitigation solution to reduce risk to an acceptable level. Similar to the risk
assessment process, the cost-benefit analysis requires strict role definitions
in order to operate effectively. Also, before conducting the cost-benefit
analysis, the Security Risk Management Team must ensure that all stakeholders,
including the Executive Sponsor, have acknowledged and agreed to the process.
During the Conducting Decision Support phase, the Security Risk Management
Team must determine how to address the key risks in the most effective and cost
efficient manner. The end result will be clear plans to control, accept,
transfer, or avoid each of the top risks identified in the risk assessment
process. The six steps of the Conducting Decision Support phase are:
- Define functional requirements.
- Select control solutions.
- Review solutions against the requirements.
- Estimate the degree of risk reduction that each control provides.
- Estimate costs of each solution.
- Select the risk mitigation strategy.
When comparing the value of a particular control to that of another, there
are no simple formulas. The process can be challenging for a variety of reasons.
For example, some controls impact multiple assets. The Security Risk Management
Team must agree on how to compare the values of controls that impact different
combinations of assets. Additionally, there are costs associated with controls
that extend beyond the implementation of those controls. Related questions to
consider include:
- How long will the control be effective?
- How many person hours per year will be required to monitor and maintain
the control?
- How much inconvenience will the control impose on users?
- How much training will be needed for those responsible for implementing,
monitoring, and maintaining the control?
- Is the cost of the control reasonable, relative to the value of the
asset?
The remainder of this chapter will discuss answers to these questions.
You will attain success during the decision support process if you follow a
clear path and if participants understand their respective roles at each step.
The following diagram illustrates how the Security Risk Management Team conducts
the decision support process. Mitigation Owners are responsible for proposing
controls that will lessen the risk and then determining the cost of each
control. For each proposed control, the Security Risk Management Team estimates
the degree of risk reduction that the control can be expected to provide. With
these pieces of information, the team can then conduct an effective cost-benefit
analysis for the control to determine whether to recommend it for
implementation. The Security Steering Committee then decides which controls will
be implemented.
|
Call Now : 800-519-
2267
Testimonials
|
If you're serious about getting certified,
this is the place to go. Definitely worth
their competitive price. Excellent
instructors, making it possible for anyone
to learn no matter what your level of
experience or knowledge.
Michael Doty
|
|
|
|
|
|
MCITP Boot Camp
,
MCSE Boot camp,
CCNA Boot Camp,
Upgrade to MCITP Boot
camp,
MCITP Enterprise admin
Certification
Boot camp Training.
All
rights reserved. ©1998 - 2015, Vibrant Worldwide Inc.
MCITP Boot camp
UK
MCITP Camp
Thailand
MCITP
RHCE Boot Camp India
MCSE Boot Camp - Proven Boot camp for MCSE at Baltimore, Maryland
MCITP, MCSE, CCNA, Certification n training guide, how mcse mcitp
ccna boot camp works
MCSE Boot Camp Proven MCSE Boot camp Training for MCSE
Certification Fast
MCSE Boot Camp Card Payment by Paypal
CCNA 801 Boot Camp by Vibrant boot camps, join MCSE camps
CCNA Boot Camp by Vibrant boot camps, join MCSE camps
CCNP Boot Camp by Vibrant boot camps, join CCNP camps
MCSE MCITP CCNA Boot Camp Card Payment by Paypal
MCSE MCITP Boot Camp location
comaprision between USA, UK, India and Thailand
MCSE Boot Camp compare Vibrant boot camps with other boot camp
provider
Comptia Security+ Boot Camp by Vibrant boot camps, join MCSE
camps
MCSE Boot Camp contact Vibrant boot camps
MCSE Boot Camp course fees Vibrant boot camps, join MCSE camps
MCSE Boot Camp FAQ by Vibrant boot camps, join MCSE camps
MCSE Boot Camp provide your Feedback here
MCSE CCNA CCNP Boot Camp inquire we call back
MCSE Boot Camp location San Francisco and Baltimore
MCITP Boot Camp MCITP 14days
all_incl MCITP Certifiation boot camp
MCITP Boot Camp MCITP Benefits
MCITP Certifiation boot camp
MCITP Boot Camp MCITP curriculum
MCITP Certifiation boot camp
MCITP Boot Camp MCITP bootcamp
details MCITP Certifiation camp
MCITP Boot Camp MCITP exam detail
MCITP Certifiation boot camp
MCSE Boot Camp MCSE Certification Camp also MCSE Training Boot
Camp
MCSE Benefits join MCSE Boot Camp by Vibrant boot camps
MCSE Curriculum join MCSE Boot Camp
MCSE Exam Detials join MCSE Boot Camp
MCSE boot camp details, join MCSE camps
MCSE MCITP Boot Camp MCSE MCITP 18days 8 Certifiation boot camp
MCSE MCITP combo Boot Camp MCITP
MCSE Benefits MCITP Certifiation boot camp
MCITP MCSE Boot Camp MCITP
curriculum MCITP Certifiation boot camp
MCSE MCITP Boot Camp MCITP MCSE
bootcamp details MCITP Certifiation camp
MCSE MCITP Boot Camp MCITP MCSE
exam detail MCITP Certifiation boot camp
MCSE MCITP CCNA Boot Camp MCSE
MCITP CCNA 23days 9 Certifiation boot camp
MCSE Security Boot Camp MCSE
14days all_incl MCSE Certifiation boot camp
MCSE Security certification benefits join boot camp now
MCSE Security Boot Camp Curriculum join MCSE camps
MCSE Security Exam Detail join MCSE boot camps
MCSE Security Boot Camp Details for MCSE Certification
MCSE Boot Camp Payment Gateway to get MCSE Certification Fast!
MCITP Boot Camp, CCNA Boot Camp
reason to join Vibrant boot camp
MCSE Boot Camp Refunds
MCSE CCNA CCNP Boot Camp Register. Join MCSE CCNA Boot Camp today
MCSE CCNA CCNP thailand bangkok Boot Camp Register. Join Thailand
MCSE CCNA Boot Camp today
MCSE Schedule CCNA Scedule CCNP Boot Camp Schedule
MCITP Boot Camp, MCSE Boot camp, CCNA Boot Camp, Special offer
Vibrant boot camp
MCSE Boot Camp Testimonials by Vibrant boot camps
MCSE Boot Camp location San Francisco and Baltimore
Virbant Boot Camp thank You Trasaction successfull
MCSE Boot Camp upgrade win2008 mcse camps
Microsoft Vista Certification Boot
Camp for Vista training boot camps
MCSE Boot Camp location San Francisco and Baltimore
bootcamp_schedule.php
cardpay.php
CCNA-boot-camp.php
certification-courses.php
certified-ethical-hacker-ceh-certified-EC-council.php
cisco-certification-courses.php
comptia_a+_bootcamp_course.php
comptia_a+_network+_boot_camp.php
comptia-certification-courses.php
compTia-network+.php
compTia-security+.php
contact_us.php
course_fees.php
course_template.php
faq_camp.php
guarantee.php
how-boot-camp-works.php
index.php
join-vibrant-as-trainer.php
locations.php
mcsa_server_2012_r2_boot_camp.php
mcsa-windows-server-2016-training-certification-boot-camp.php
mcse-cloud-platform-infrastructure-azure-track.php
mcse-cloud-platform-infrastructure-security-with-mcsa-windows-server-2016-training-certification-boot-camp.php
mcse-cloud-platform-infrastructure-with-mcsa-windows-server-2012-R2-training-certification-boot-camp.php
mcse-productivity-exchange-server-2016.php
microsoft-certification-courses.php
microsoft-mcse-messaging-certification-training-course.php
msca-windows-2016-upgrade.php
msce-windows-2008-to-2016-upgrade.php
msce-windows-2016-upgrade.php
mta-it-infrastructure-windows-server-training-certification.php
onsite-training.php
our-clients.php
photogallery.php
reason_to_join_vibrant_boot_camp.php
recaptchalib.php
refund.php
register.php