The problem it solves
Without knowing which assets exist, where they are and what they are worth, no security decision is defensible. Risk is discussed in the abstract and accepted without anyone formally accepting it.
Who it is for
- Organisations preparing for certification;
- Newly appointed security leads;
- Entities processing personal data at scale.
Deliverables
- Risk management methodology;
- Inventory of information assets;
- Assessed risk matrix;
- Treatment plan with accepted residual risks.
Method
- 01
Inventory
Assets and dependencies.
- 02
Assess
Threats and impacts.
- 03
Treat
Measures and deadlines.
- 04
Accept
Residual risk formally accepted.
Regulatory basis
- ISO/IEC 27005 and ISO 31000;
- Article 32 GDPR, on security of processing.
Expected results
- Risks known and ranked;
- Decisions documented and defensible;
- A basis for the annual security plan.