|
VIBRANTBOOTCAMP.CO.UK |
|
MCSE MCITP Boot Camp |
|
|
| MCITP MCSE CCNA CCNP Boot camp UK : |
Vibrant
Microsoft Notes :
Join Vibrant MCSE
Boot camp Training in UK.
|
This guide is technology agnostic and references many industry accepted standards for managing security risk. It is an important example of Microsoft's commitment to delivering quality guidance to help customers secure their Information Technology (IT) infrastructures. This guide incorporates real-world experiences from Microsoft IT and also includes input from Microsoft customers and partners. This guide comprises six chapters and four appendices.
Chapter 1 introduces The Security Risk Management Guide (SRMG) and provides a brief overview of subsequent chapters. It also provides information about the following:
Chapter 2 lays a foundation and provides context for the SRMG by reviewing other approaches to security risk management and related considerations, including how to determine your organization's risk management maturity level.
Chapter 3 provides a more detailed look at the four phases of the SRMG process while introducing some of its important concepts and keys to success. The chapter also offers advice on preparing for the program by planning effectively and placing strong emphasis on building a solid Security Risk Management Team that has well defined roles and responsibilities.
Chapter 4 addresses the first phase, Assessing Risk, in detail. Steps in this phase include planning, data gathering, and risk prioritization. Risk prioritization itself is comprised of summary and detailed levels, balancing qualitative and quantitative approaches in order to provide reliable risk information within reasonable trade-offs of time and effort. The output from the Assessing Risk phase is a list of significant risks with detailed analysis that the team can use to make business decisions during the next phase of the process.
Chapter 5 addresses the second phase, Conducting Decision Support. During this phase, teams determine how to address the key risks in the most effective and cost efficient manners. Teams identify controls; estimate costs; assess the degree of risk reduction; and then determine which controls to implement. The output of the Conducting Decision Support phase is a clear and actionable plan to control or accept each of the top risks identified in the Assessing Risk phase.
Chapter 6 addresses the final two phases of the SRMG: Implementing Controls and Measuring Program Effectiveness. During the Implementing Controls phase, the Mitigation Owners create and execute plans based on the list of control solutions that emerged during the decision support process. When the first three phases of the security risk management process are complete, organizations should estimate their progress with regard to security risk management as a whole. The final phase, Measuring Program Effectiveness, introduces the concept of a "Security Risk Scorecard" to assist in this effort. |
|
|
|
|