Security Baselines
A security baseline refers to the minimum security requirement across the organization. The baseline may be different in accordance with asset classification. For highly classified assets, the baseline will be more stringent. For example, for low-classified assets, the baseline can be single-factor authentication. However, it would increase to two-factor authentication for high-classified assets.
Baseline security should form a part of the control objectives. The baseline should be reviewed at regular intervals to ensure that it is aligned with the organization's overall objectives.
Risk Communication
The communication of risk management activities is key to the effective implementation of the risk management strategy. Communication should involve all relevant stakeholders, and communication channels should enable interaction in both directions. That is, management should be able to communicate with end users and end users should be able ...