Control Design and Implementation
As we learned earlier in this book, risk mitigation is one of the most common responses in risk management. A risk manager needs to be aware of adequate risk mitigation techniques to reduce the risk to an acceptable level. Control design and implementation is one of the most important steps in risk mitigation. With the ever-changing threat landscape, the controls that are implemented today may become irrelevant tomorrow, and therefore, controls should be reviewed periodically to determine and continue their effectiveness.
This chapter aims to help you learn about the different types of controls, standards, frameworks, and methodologies for control design and selection, as well as how to implement them effectively. We will also learn about several control techniques and methods to evaluate them effectively.
In this chapter, we will cover the following topics:
- Control categories
- Control design and selection
- Control implementation...