2 NIST S 4 Phases For Risk Assessments 1687434774

You might also like

You are on page 1of 8

4 Phases

of
Risk Assessment

As per NIST SP 800-30

https://www.linkedin.com/in/chinmaykulkarni22/
Risk Assessment
Phases

Framing Identifying
Risk Risk

Responding Monitoring
to Risk Risk

https://www.linkedin.com/in/chinmaykulkarni22/
Risk Assessment
Phases
Understand the business

Define & document the environment

Framing Decide Risk Assessment Approach

Risk
Define how risk decisions will be made

Qualitative vs Quantitative vs Semi

https://www.linkedin.com/in/chinmaykulkarni22/
Risk Assessment
Phases
Document threat environment

Identify threat scenarios & actors

Risk Identify vulnerabilities

Identification
Calculate likelihood & Impact

Consider current security controls

https://www.linkedin.com/in/chinmaykulkarni22/
Risk Assessment
Phases

Document risk remediation plans

Accept, Mitigate, Avoid or Transfer?


Responding
to Risk Derive Risk Ratings

Focus on High Risks first

https://www.linkedin.com/in/chinmaykulkarni22/
Risk Assessment
Phases

Perform effective monitoring

Monitor high risks for remediation


Monitoring
Risk Track risks over time

Perform Audits ensuring risk treatment

https://www.linkedin.com/in/chinmaykulkarni22/
Save it for later

https://www.linkedin.com/in/chinmaykulkarni22/
Connect with me
to learn more about

ITGC Testing

Certified Information Systems Auditor (CISA)

ISO 27001 ISMS

ISO 27701 PIMS

Data Privacy

IT Auditing

Risk Management

https://www.linkedin.com/in/chinmaykulkarni22/

You might also like