Security Risk Management
Bureau 24 uses a 4 step process to protect you, your networks, data and computers.
Assessing Risk. This phase combines aspects
of both quantitative and qualitative risk assessment methodologies.
A qualitative approach is used to quickly triage the entire list
of security risks. The most serious risks
identified are then examined in more detail using a quantitative
approach. The result is a relatively short list of the most important
risks that have been examined in detail.
Conducting Decision Support. The list created during the risk assessment phase is used during the decision support phase to propose and evaluate potential control solutions, and the best ones for mitigating the top risks are then recommended to the organization’s Security Steering Committee.
Implementing Controls. During this third phase, the mitigation owners actually put control solutions in place.
Measuring Program Effectiveness. The fourth phase is used to verify that the controls are actually providing the expected degree of protection, and to watch for changes in the environment, such as new business applications or attack tools that might change the organization’s risk profile. Additionally, current controls should be reevaluated for newer, similar controls that are more effective because of changes in technology and other advancements in security protection. |