官术网_书友最值得收藏!

Risk assessment policy

The risk assessment policy establishes the rules for the organization that explains how the organization will conduct risk assessments at the organizational, operational, and system-specific level.

What the risk assessment policy should address:

  • Assessing risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and inpiduals, resulting from the operation of organizational information systems and the associated processing, storage, or transmission of organizational information
  • Scanning for vulnerabilities in the information system and applications periodically and when new vulnerabilities affecting the system are identified
  • Remediating vulnerabilities in accordance with assessments of risk
主站蜘蛛池模板: 清水县| 五指山市| 岳西县| 保靖县| 佳木斯市| 木兰县| 永吉县| 棋牌| 白水县| 华坪县| 桐庐县| 河西区| 红河县| 鲁甸县| 道真| 金溪县| 固原市| 达州市| 景德镇市| 大悟县| 改则县| 清丰县| 北宁市| 香河县| 南汇区| 桂林市| 西平县| 广灵县| 长寿区| 吉木萨尔县| 吉木乃县| 巩义市| 沽源县| 连江县| 泗洪县| 确山县| 佛学| 罗甸县| 渝中区| 游戏| 桂东县|