Feel free to discuss any topics relating to cybersecurity with the rest of the security community in this forum.
Risk mgmt policy
- o_boiboi77
- Topic Author
- Offline
- Junior Member
- Posts: 26
- Thank you received: 0
Am working on a risk mgmt policy, seems very complex n wld like to consult the gurus here for some advice. =)
Please Log in or Create an account to join the conversation.
- o_penguin78
- Offline
- Junior Member
- Posts: 39
- Thank you received: 0
hi all. nice to discuss on risk mgmt, how often does one need to review the risk assessment policy? quarterly or annually?
Please Log in or Create an account to join the conversation.
- o_icemanssl22
- Offline
- Premium Member
- Posts: 142
- Thank you received: 0
I guess it come down to budget, resources, IT infrastructure and most importance, industies you are in.
You can reference to the statistics report done in US as sample and decide the review time frame:
www.hackmageddon.com/2015/05/12/april-20...-attacks-statistics/
So, some industries need more assessment regularly then the rest. Is management call.
Please Log in or Create an account to join the conversation.
- o_penguin78
- Offline
- Junior Member
- Posts: 39
- Thank you received: 0
OMG, so much attacks taking place! Hmm.. guess it's always wise to do regular review to ensure all controls are properly in place. stress!
Please Log in or Create an account to join the conversation.
- o_icemanssl22
- Offline
- Premium Member
- Posts: 142
- Thank you received: 0
When ACL is concern; remember to strike a balance in order not to affect business workflow. Happy defending.!
Please Log in or Create an account to join the conversation.
- o_moomoo77
- Offline
- Senior Member
- Posts: 57
- Thank you received: 0
just to share my views. risk mgmt has to be taken seriously, tis will affect business flow/operations. pay careful attention when evaluating risks and plugging it with the right mitigating controls.
Please Log in or Create an account to join the conversation.