Quick reference
Ideally, your company’s risk management program should include the following:
Depending on where your company is in terms of building out its risk management program, the processes, planning, and remediation are as follows:
- Basic: Start-ups
- Medium: Companies 3–5 years into their compliance journey
- Advanced: Companies who understand the importance of security and have aligned their risk management program with their business mission and objectives
Ideally, your company’s risk management should include the following:
- Basic:
- Alignment with your company’s budget
- Asset inventory
- Identifying risks and tracking them in a risk register
- Medium:
- Co-ordination with senior-level management
- Reporting of risks and tracking this up to senior management
- Define your most critical assets
- Advanced:
- Alignment with your company’s mission and objectives
- Key performance indicators (KPIs)
- Monitoring of controls “continual...