Risk Management
- •
def
- •
identifying, qualifying, and planning for potential internal and external threats before they become a problem
- •
- •
assessment types
- •
one-time — tied to a specific event (an acquisition, new equipment, a novel threat)
- •
continuous — built into an existing process (e.g., change control requiring a risk assessment)
- •
ad hoc — performed when a specific situation calls for it, without a standing formal process
- •
recurring — performed on a standard interval, sometimes mandated (e.g., PCI DSS requires annual risk assessments)
- •
- •
related