Now that we have identified risk - how do we control it? How do we know what risks should be addressed and what should not be addressed?
There are four main strategies for controlling risk...
- Avoid - Do not engage in the activity that incurs risk or create an environment where there is no risk for the activity.
- Reduce or mitigate - Develop controls to reduce the risk to an acceptable level.
- Transfer- Move the risk to another entity, for example, outsourced vendor.
- Accept - Choose to not address the risk based on completion of due diligence.
What helps an organization understand which strategy to use? Ultimately feasibility and cost benefit analysis tools will create the picture for an organization to weigh the strategy to pursue. For example, if the cost is too high in comparison to the benefit maybe this risk is a candidate for acceptance or mitigation strategy.
There are several standard methodologies for risk management and risk control. These include templates and tools for calculating risk.
OCTAVE - http://www.cert.org/octave/
No comments:
Post a Comment