官术网_书友最值得收藏!

Risk assessment policy

The risk assessment policy establishes the rules for the organization that explains how the organization will conduct risk assessments at the organizational, operational, and system-specific level.

What the risk assessment policy should address:

  • Assessing risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and inpiduals, resulting from the operation of organizational information systems and the associated processing, storage, or transmission of organizational information
  • Scanning for vulnerabilities in the information system and applications periodically and when new vulnerabilities affecting the system are identified
  • Remediating vulnerabilities in accordance with assessments of risk
主站蜘蛛池模板: 嵩明县| 潼关县| 京山县| 射洪县| 灵寿县| 渝中区| 柞水县| 怀来县| 临湘市| 孟津县| 团风县| 鹿邑县| 泰安市| 洛隆县| 富平县| 鸡泽县| 连山| 呼伦贝尔市| 会宁县| 卓尼县| 广灵县| 静安区| 沂源县| 烟台市| 宁波市| 宝鸡市| 泽库县| 南华县| 沐川县| 莱阳市| 和硕县| 南岸区| 浙江省| 兴文县| 凤阳县| 西丰县| 陵水| 安岳县| 绥芬河市| 正宁县| 聂拉木县|