Risk management is the identification, evaluation, and prioritization of risks (as defined in ISO 31000), followed by the coordinated and economical application of resources to minimize, monitor, and control the probability or impact of unfortunate events or to maximize the realization of opportunities:
Following steps are covered in risk management:
- Monitor the assets: Once the actions that were defined in the risk management plan have been implemented, you will need to monitor the assets for the realization of security risks:
- Define the elements of value
- Identify the assets
- Protect the assets (where vulnerability management will take an important part)
- Track changes to risks: As time progresses, changes to your organization's hardware, software, personnel, and business processes will add and obsolete security risks. Similarly, threats...