▲ Back to Top
Information Security Risk Management
This management is a set of activities to control and direct the identification and administration of information security risks, in order to achieve business objectives. Risk is a characteristic of business life, which is why it is necessary to have control over them.
STAGES
1. PLAN
2. DO
3. VERIFY
4. ACT
-
- Define the methodology for the identification, evaluation, and treatment of risk.
-
- Establish the business resources against which the impacts will be measured.
-
- Establish the criteria for defining acceptable risk levels.
-
- Identify how the plans for implementing risk treatment controls will be deployed and executed.
-
- Identify vulnerabilities, threats, and information security risks.
-
- Determine the probability of the risk occurring.
-
- Determine the business impact on its own resources.
-
- Define risk treatment plans.
-
- Review the assessments made on information assets if changes occur in the business or technology.
-
- Conduct a quality review of the information recorded in the inventory.
-
- Conduct compliance audits of treatment and handling in accordance with the stipulated classification levels.
-
- Update the asset inventory information.
-
- Advance the recommendations resulting from the audits performed.
Documents
ESG-SSI-P12- INFORMATION SECURITY AND PRIVACY RISK MANAGEMENT
There are no documents for this filter.
OTRAS ETAPAS DEL MODELO
SGSI
SGSI
SGSI
SGSI
