Risk assessment and prioritization
With the threat model in place, we can assess and prioritize risks based on the likelihood of their occurrence and potential impact. This risk-based approach ensures that resources are allocated efficiently, with an initial focus on mitigating the most significant threats.
The process will be guided and signed off by the risk owner. A risk owner is an individual who’s responsible for managing and mitigating a specific risk area to an organization’s objectives.
In its simplest form, the risk score of each threat can be calculated as follows:
Risk Score = Likelihood x Impact
Organizations will have their own risk assessment framework that expands the preceding formula to model impact at different levels of detail and granularity, often measuring financial cost.
Without a formal risk model, we need to agree on an approach with the risk owner. There are some simple methods we can use to start capturing and communicating risk...