You are on page 1of 2

NIST RISK ASSESSMENT

‫ ان عملية تقييم المخاطر يتم تنفيذها على المستويات الهرمية الثالثة الدارة المخاطر‬:‫الهدف والتطبيق‬ -1.1
)‫عملياتية‬/‫تكتيكية‬/‫وهي(استراتيجية‬
1.2- 1.3 RELATED PUBLICATIONS The risk assessment approach described in this publication is
supported by a series of security standards and guidelines necessary for managing information
security risk. In addition to this publication, the Special Publications developed by the Joint Task
Force Transformation Initiative supporting the unified information security framework for the
federal government include: • Special Publication 800-39, Managing Information Security Risk:
Organization, Mission, and Information System View; 11 • Special Publication 800-37, Guide for
Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle
Approach; • Special Publication 800-53, Recommended Security Controls for Federal
Information Systems and Organizations; and • Special Publication 800-53A, Guide for Assessing
the Security Controls in Federal Information Systems and Organizations: Building Effective
Security Assessment Plans.

:‫الفصل الثاني‬
:‫األساسيات‬
.‫مفاهيم أساسية مرتبطة ب تقييم المخاطر‬
:‫ عملية إدارة المخاطر‬-2.1
‫تقييم المخاطر هو عنصر هام ضمن عملية إدارة المخاطر المنظمة التي تشمل إدارة مخاطر أمن المعلومات ومخاطر التي‬
:‫ وتتضمن عملية إدارة المخاطر العناصر األتية‬،‫تعيق المنطمة من تحقيق هدفها والمخاطر المرتبطة بتقانة المعلومات‬

‫مثال عن بنك‬/ ‫ تتضمن تعريف النطاق واألهداف والقيود وفهم هدف المنظمة‬:)FARMING RISK( ‫تأطير المخاطر‬
:/ABC
Framing Risk:
Context: A bank, let's call it ABC Bank, operates in an environment where interest rates
fluctuate.
Scope: ABC Bank offers a range of financial products, including loans and deposits, and its
profitability is sensitive to changes in interest rates.
Objectives: The bank aims to maximize shareholder value, provide competitive financial
products, and ensure financial stability.
Constraints: Regulatory requirements, market conditions, and customer expectations are
considered.

‫تقييم المخاطر‬
‫االستجابة للمخاطر‬
‫مراقبة المخاطر‬

You might also like