|
|
Planning
Proper risk assessment planning is critical to the success of the entire risk
management program. Failure to adequately align, scope, and gain acceptance of
the Assessing Risk phase diminishes the effectiveness of the other phases in the
larger program. Conducting risk assessments can be a complicated process that
requires significant investment to complete. Tasks and guidance critical to the
planning step are covered in the next section of this chapter.
Facilitated Data Gathering
After planning, the next step is to gather risk related information from
stakeholders across the organization; you will also use this information in the
Conducting Decision Support phase. The primary data elements collected during
the facilitated data gathering step are:
- Organizational assets — Anything of value to the business.
- Asset description — Brief explanation of each asset, its worth,
and ownership to facilitate common understanding throughout the Assessing
Risk phase.
- Security threats — Causes or events that may negatively impact an
asset, represented by loss of confidentiality, integrity, or availability of
the asset.
- Vulnerabilities — Weaknesses or lack of controls that may be
exploited to impact an asset.
- Current control environment — Description of current controls and
their effectiveness across the organization.
- Proposed controls — Initial ideas to reduce risk.
The facilitated data gathering step represents the bulk of the cross-group
collaboration and interaction during the Assessing Risk phase. The third section
in this chapter covers data gathering tasks and guidance in detail.
Risk Prioritization
During the facilitated data gathering step, the Security Risk Management Team
begins sorting the large amount of information collected to prioritize risks.
The risk prioritization step is the first one within the phase that involves an
element of subjectivity. Prioritization is subjective in nature because, after
all, the process essentially involves predicting the future. Because the
Assessing Risk output drives future Information Technology (IT) investments,
establishing a transparent process with defined roles and responsibilities is
critical to gain acceptance of the results and motivate action to mitigate
risks. The Microsoft security risk management process provides guidance to
identify and prioritize risks in a consistent and repeatable way. An open and
reproducible approach helps the Security Risk Management Team to reach consensus
quickly, minimizing potential delays caused by the subjective nature of risk
prioritization. The fourth section in this chapter covers prioritization tasks
and guidance in detail.
Required Inputs for the Assessing Risk Phase
Each step in the Assessing Risk phase contains a specific list of
prescriptive tasks and associated inputs. The phase itself requires a well-built
foundation as opposed to specific inputs. As outlined in Chapter 1, the
Assessing Risk phase requires security leadership in the form of executive
support, stakeholder acceptance, and defined roles and responsibilities. The
following sections address these areas in detail.
Participants in the Assessing Risk Phase
Assessing risk requires cross-group interaction and for different
stakeholders to be held responsible for tasks throughout the process. A best
practice to reduce role confusion throughout the process is to communicate the
checks and balances built into the risk management roles and responsibilities.
While you are conducting the assessment, communicate the roles that stakeholders
play and assure them the Security Risk Management Team respects these
boundaries. The following table summarizes the roles and primary
responsibilities for stakeholders in this phase of the risk management process.
|
Call Now : 800-519-
2267
Testimonials
|
If you're serious about getting certified,
this is the place to go. Definitely worth
their competitive price. Excellent
instructors, making it possible for anyone
to learn no matter what your level of
experience or knowledge.
Michael Doty
|
|
|
|
|
|
MCITP Boot Camp
,
MCSE Boot camp,
CCNA Boot Camp,
Upgrade to MCITP Boot
camp,
MCITP Enterprise admin
Certification
Boot camp Training.
All
rights reserved. ©1998 - 2015, Vibrant Worldwide Inc.
MCITP Boot camp
UK
MCITP Camp
Thailand
MCITP
RHCE Boot Camp India
MCSE Boot Camp - Proven Boot camp for MCSE at Baltimore, Maryland
MCITP, MCSE, CCNA, Certification n training guide, how mcse mcitp
ccna boot camp works
MCSE Boot Camp Proven MCSE Boot camp Training for MCSE
Certification Fast
MCSE Boot Camp Card Payment by Paypal
CCNA 801 Boot Camp by Vibrant boot camps, join MCSE camps
CCNA Boot Camp by Vibrant boot camps, join MCSE camps
CCNP Boot Camp by Vibrant boot camps, join CCNP camps
MCSE MCITP CCNA Boot Camp Card Payment by Paypal
MCSE MCITP Boot Camp location
comaprision between USA, UK, India and Thailand
MCSE Boot Camp compare Vibrant boot camps with other boot camp
provider
Comptia Security+ Boot Camp by Vibrant boot camps, join MCSE
camps
MCSE Boot Camp contact Vibrant boot camps
MCSE Boot Camp course fees Vibrant boot camps, join MCSE camps
MCSE Boot Camp FAQ by Vibrant boot camps, join MCSE camps
MCSE Boot Camp provide your Feedback here
MCSE CCNA CCNP Boot Camp inquire we call back
MCSE Boot Camp location San Francisco and Baltimore
MCITP Boot Camp MCITP 14days
all_incl MCITP Certifiation boot camp
MCITP Boot Camp MCITP Benefits
MCITP Certifiation boot camp
MCITP Boot Camp MCITP curriculum
MCITP Certifiation boot camp
MCITP Boot Camp MCITP bootcamp
details MCITP Certifiation camp
MCITP Boot Camp MCITP exam detail
MCITP Certifiation boot camp
MCSE Boot Camp MCSE Certification Camp also MCSE Training Boot
Camp
MCSE Benefits join MCSE Boot Camp by Vibrant boot camps
MCSE Curriculum join MCSE Boot Camp
MCSE Exam Detials join MCSE Boot Camp
MCSE boot camp details, join MCSE camps
MCSE MCITP Boot Camp MCSE MCITP 18days 8 Certifiation boot camp
MCSE MCITP combo Boot Camp MCITP
MCSE Benefits MCITP Certifiation boot camp
MCITP MCSE Boot Camp MCITP
curriculum MCITP Certifiation boot camp
MCSE MCITP Boot Camp MCITP MCSE
bootcamp details MCITP Certifiation camp
MCSE MCITP Boot Camp MCITP MCSE
exam detail MCITP Certifiation boot camp
MCSE MCITP CCNA Boot Camp MCSE
MCITP CCNA 23days 9 Certifiation boot camp
MCSE Security Boot Camp MCSE
14days all_incl MCSE Certifiation boot camp
MCSE Security certification benefits join boot camp now
MCSE Security Boot Camp Curriculum join MCSE camps
MCSE Security Exam Detail join MCSE boot camps
MCSE Security Boot Camp Details for MCSE Certification
MCSE Boot Camp Payment Gateway to get MCSE Certification Fast!
MCITP Boot Camp, CCNA Boot Camp
reason to join Vibrant boot camp
MCSE Boot Camp Refunds
MCSE CCNA CCNP Boot Camp Register. Join MCSE CCNA Boot Camp today
MCSE CCNA CCNP thailand bangkok Boot Camp Register. Join Thailand
MCSE CCNA Boot Camp today
MCSE Schedule CCNA Scedule CCNP Boot Camp Schedule
MCITP Boot Camp, MCSE Boot camp, CCNA Boot Camp, Special offer
Vibrant boot camp
MCSE Boot Camp Testimonials by Vibrant boot camps
MCSE Boot Camp location San Francisco and Baltimore
Virbant Boot Camp thank You Trasaction successfull
MCSE Boot Camp upgrade win2008 mcse camps
Microsoft Vista Certification Boot
Camp for Vista training boot camps
MCSE Boot Camp location San Francisco and Baltimore
bootcamp_schedule.php
cardpay.php
CCNA-boot-camp.php
certification-courses.php
certified-ethical-hacker-ceh-certified-EC-council.php
cisco-certification-courses.php
comptia_a+_bootcamp_course.php
comptia_a+_network+_boot_camp.php
comptia-certification-courses.php
compTia-network+.php
compTia-security+.php
contact_us.php
course_fees.php
course_template.php
faq_camp.php
guarantee.php
how-boot-camp-works.php
index.php
join-vibrant-as-trainer.php
locations.php
mcsa_server_2012_r2_boot_camp.php
mcsa-windows-server-2016-training-certification-boot-camp.php
mcse-cloud-platform-infrastructure-azure-track.php
mcse-cloud-platform-infrastructure-security-with-mcsa-windows-server-2016-training-certification-boot-camp.php
mcse-cloud-platform-infrastructure-with-mcsa-windows-server-2012-R2-training-certification-boot-camp.php
mcse-productivity-exchange-server-2016.php
microsoft-certification-courses.php
microsoft-mcse-messaging-certification-training-course.php
msca-windows-2016-upgrade.php
msce-windows-2008-to-2016-upgrade.php
msce-windows-2016-upgrade.php
mta-it-infrastructure-windows-server-training-certification.php
onsite-training.php
our-clients.php
photogallery.php
reason_to_join_vibrant_boot_camp.php
recaptchalib.php
refund.php
register.php