Risk assessment
As we discussed in the previous section, risk assessment includes the following three components:
- Risk identification
- Risk analysis (to determine the level of risk; that is, whether the risk is high, medium, or low)
- Risk evaluation (to determine whether the risk is acceptable or whether risk treatment is required)
Asset identification
The first and most important step in a risk assessment process is to identify and list all the information assets and determine their value based on criticality or sensitivity. In the absence of a detailed asset inventory, you may miss out on protecting some significant assets. Assets can be in the form of people, processes, system and network components, databases, or any other factor that can have an impact on business processes. Assets aren't only tangible assets but intangible assets such as the reputation of the organization.
Asset valuation
Once all the assets have been identified, the next...