GRC | NIST 800-30 Guide for Conducting Risk Assessments​. Enterprise Organizational Risk Security

แชร์
ฝัง
  • เผยแพร่เมื่อ 24 มิ.ย. 2024
  • GRC | NIST 800-30 Guide for Conducting Risk Assessments​. Enterprise Organizational Risk SecurityRisk assessment is one of the fundamental components of an organizational risk management process as described in NIST Special Publication 800-39. Risk assessments are used to identify, estimate, and prioritize risk to organizational operations (i.e., mission, functions, image, and reputation), organizational assets, individuals, other organizations, and the Nation, resulting from the operation and use of information systems. The purpose of risk assessments is to inform decision makers and support risk responses by identifying: (i) relevant threats to organizations or threats directed through organizations against other organizations; (ii) vulnerabilities both internal and external to organizations; (iii) impact (i.e., harm) to organizations that may occur given the potential for threats exploiting vulnerabilities; and (iv) likelihood that harm will occur. The end result is a determination of risk (i.e., typically a function of the degree of harm and likelihood of harm occurring).
  • วิทยาศาสตร์และเทคโนโลยี

ความคิดเห็น • 1

  • @Cwhitlock-StudyGRC
    @Cwhitlock-StudyGRC 2 วันที่ผ่านมา

    Another great stream, thank you for your time and value to the community!