top of page
Search

Assessing the Risk in an Enterprise

  • Writer: Abhilasha
    Abhilasha
  • Jul 8, 2024
  • 1 min read
  1. Facilitated Data Gathering:

  • Collecting information about organizational assets, their descriptions, security threats they face, vulnerabilities, current controls in place, and proposed new controls.

  • Key to success: Collaboratively meeting with stakeholders, building support, maintaining a positive dialogue, and being well-prepared.

  1. Identifying and Classifying Assets:

  • Assets are anything valuable to an organization, classified based on their impact:

  • High impact: Critical to business operations.

  • Moderate impact: Significant but not critical.

  • Low impact: Essential but replaceable.

  1. Organizing Risk Information:

  • Structuring discussions around key questions:

  • What assets need protection?

  • How valuable are these assets?

  • What risks threaten these assets?

  • How might these risks cause damage?

  • How exposed are these assets to risk?

  • What mitigations are currently in place or planned?

  1. Estimating Asset Exposure:

  • Exposure refers to potential damage to an asset:

  • High exposure: Severe or total loss.

  • Medium exposure: Limited or moderate loss.

  • Low exposure: Minor or no loss.

  1. Estimating Threat Probability:

  • Assessing the likelihood of threats and vulnerabilities:

  • High probability: Likely to occur within a year.

  • Medium probability: Expected within two to three years.

  • Low probability: Not expected within three years.


 
 
 

Recent Posts

See All
PE internals

Linked Libraries and Functions Imported Functions: Definition: These are functions used by a program that are actually stored in...

 
 
 
OS internals

Privilege Separation Concept: Modern operating systems separate user applications (untrusted) from critical operating system components...

 
 
 
Memory Management in short

Address Space CPU Access: To run instructions and access data in main memory, the CPU needs unique addresses for that data. Definition:...

 
 
 

Comments


Subscribe Form

Thanks for submitting!

©2021 by just dump 1. Proudly created with Wix.com

bottom of page