1Introduction
Risk management systematically identifies, analyses, evaluates and treats information risks; it is CISSP’s first domain and the core of ISO 27001.
2Discussion
Start with assets, then threats and vulnerabilities.
Estimate likelihood and impact, qualitatively or quantitatively, to prioritise.
Treat by mitigating, transferring, avoiding or accepting; business owners decide on residual risk.
3Conclusion
Repeat periodically and report to leadership.
Sources
همفکران فناوری شریفThis article summarises the official sources cited, prepared by the Hamfekran Fanavari Sharif team for finance leaders.
Want to see these solutions in your organisation?Book a free demo
همفکران فناوری شریف

