The Four Phases of the Microsoft Security Risk Management Process
Chapter 2, "Survey of
Risk Management Practices," introduced the Microsoft security risk management
process and defined risk management as an ongoing process with four primary
phases:
- Assessing Risk — Identify and prioritize risks to the business.
- Conducting Decision Support — Identify and evaluate control
solutions based on a defined cost-benefit analysis process.
- Implementing Controls — Deploy and operate control solutions to
reduce risk to the business.
- Measuring Program Effectiveness — Analyze the risk management
process for effectiveness and verify that controls are providing the
expected degree of protection.
This four-part risk management cycle summarizes the Microsoft security risk
management process and is also used to organize content throughout this guide.
Before defining specific practices within the Microsoft security risk
management process, however, it is important to understand the larger risk
management process and its components. Each phase of the cycle contains
multiple, detailed steps. The following list outlines each step to help you
understand the importance of each one in the guide as a whole:
- Assessing Risk phase
- Plan data gathering — Discuss keys to success and preparation
guidance.
- Gather risk data — Outline the data collection process and analysis.
- Prioritize risks — Outline prescriptive steps to qualify and
quantify risks.
- Conducting Decision Support phase
- Define functional requirements — Define functional requirements to
mitigate risks.
- Select possible control solutions — Outline approach to identify
mitigation solutions.
- Review solution — Evaluate proposed controls against functional
requirements.
- Estimate risk reduction — Endeavor to understand reduced exposure or
probability of risks.
- Estimate solution cost — Evaluate direct and indirect costs
associated with mitigation solutions.
- Select mitigation strategy — Complete the cost-benefit analysis to
identify the most cost effective mitigation solution.
- Implementing Controls phase
- Seek holistic approach — Incorporate people, process, and technology
in mitigation solution.
- Organize by defense-in-depth — Organize mitigation solutions across
the business.
- Measuring Program Effectiveness phase
- Develop risk scorecard — Understand risk posture and progress.
- Measure program effectiveness — Evaluate the risk management program
for opportunities to improve
|
 |
Why Vibrant?
Course Fees
FAQ
Contact US
Testimonials
Site map
links
Home
Index
270
290
291
293
294
298
299
Sec+
801
routing
811
821
831.
MCSE boot camp,
Vibrant MCSE Boot Camp,
UK,
MCSE Boot Camp,
USA,
MCSE Boot Camp,
Japan,
MCSE
Boot
Camp,
boot camps,
MCSE Boot camp training,
MCSE boot camp
server,
MCSE boot camp
Microsoft,
MCSE boot camp 2003,
MCSE boot camp UK,
MCSE boot camp India,
MCSE boot camp
USA,
MCSE boot camp
San Mateo,
MCSE boot camp California,
MCSE boot camp CA,
MCSE boot camp
security, MCSE
boot camp exam,
MCSE boot camp school,
MCSE boot camp
windows,
MCSE boot camp
vibrant,
CCNA boot camp,
Guaranteed CCNA boot camp provider,
CCNA boot camp certification,
CCNA boot camp training,
CCNA boot camp
UK,
CCNA boot camp
USA,
CCNA boot camp
San Mateo,
CCNA boot camp California,
CCNA boot camp CA,
CCNA bootcamp exam,
CCNA bootcamp school,
CCNA bootcamp
best,
CCNA bootcamp,
CCNP boot camp,
Guaranteed
CCNP boot camp provider,
CCNP boot camp
certification,
CCNP boot camp training,
CCNP boot camp
UK,
CCNP boot camp
India,
CCNP boot camp
San Mateo,
CCNP bootcamp
California,
CCNP boot camp
CA,
CCNP bootcamp
exam,
CCNP bootcamp
school,
CCNP bootcamp
vibrant,
MCSE bootcamp,
Guaranteed MCSE bootcamp provider,
MCSE Bootcamp certification,
MCSE Bootcamp training,
MCSE Bootcamp server,
MCSE Bootcamp Microsoft,
MCSE Bootcamp 2003,
MCSE Bootcamp
UK,
MCSE Bootcamp
India,
MCSE Bootcamp
USA, MCSE Bootcamp San Mateo, MCSE Bootcamp
California, MCSE Bootcamp CA, MCSE Bootcamp security, MCSE Bootcamp
exam, MCSE Bootcamp school, MCSE Bootcamp longest, MCSE Bootcamp easy,
MCSE Bootcamp best, MCSE Bootcamp windows,
MCSE Bootcamp
vibrant :
MCITP Boot Camp Thailand :
MCITP Certification camp :
Mayank Desai :
Rotary India :
Rotarian Ashok Mahajan :
photos Mayank
|
|