Regulated Incident Management Ecosystem Versão portuguesa

Service sheet SO-04

Risk Assessment and Management

Definition of the methodology, asset inventory, risk assessment and a treatment plan approved by the management body.

The problem it solves

Without knowing which assets exist, where they are and what they are worth, no security decision is defensible. Risk is discussed in the abstract and accepted without anyone formally accepting it.

Who it is for

  • Organisations preparing for certification;
  • Newly appointed security leads;
  • Entities processing personal data at scale.

Deliverables

  • Risk management methodology;
  • Inventory of information assets;
  • Assessed risk matrix;
  • Treatment plan with accepted residual risks.

Method

  1. 01

    Inventory

    Assets and dependencies.

  2. 02

    Assess

    Threats and impacts.

  3. 03

    Treat

    Measures and deadlines.

  4. 04

    Accept

    Residual risk formally accepted.

Regulatory basis

  • ISO/IEC 27005 and ISO 31000;
  • Article 32 GDPR, on security of processing.

Expected results

  • Risks known and ranked;
  • Decisions documented and defensible;
  • A basis for the annual security plan.

Security that is not measured is not managed

Start with a maturity assessment or ask for a proposal to structure the role.