Risk management planning
Risk Identification
Negative Risk or Positive risk or Threats
Threats
Avoid Exploit
Transfer Share
Mitigate (minimize) enhance
Accept
Risk Identification
Risk measurement and assessment,
Risk mitigation,
Risk reporting and monitoring,
Risk governance
Step Description
Prepare ➢ focuses on getting the organization ready to adopt a formalized risk management strategy
Categoriz ➢ organizations begin assessing the risks that have been identified.
➢ This may mean assessing the impact of the various risks and prioritizing the risks that need
e to be addressed.
Select ➢ involves choosing the controls that will be used to protect affected systems to minimize or
mitigate the risks that have been identified.
Implemen ➢ This is where the selected controls are put into place in an effort to head off risks that might
exist.
t
Assess ➢ It seeks to determine whether the selected controls were implemented correctly and if those
controls are delivering the desired result
➢ This means making sure any mechanisms that have been implemented are reducing risks in a
quantifiable way without accidentally introducing new risks in the process.
Authorize ➢ the authorize phase is more of an overview by senior members of the organization who are
looking to make sure that risk mitigation strategies are working