|
Self-Assessment Processes (SAP)
Widely documented in numerous case studies, it has been proven that world-class organizations have benefited from the design and implementation of Self-Assessment Processes (SAP) that foster a "culture of self-improvement". The IT Governance Institute strongly suggests that organizations should "Create and maintain a risk management framework." The ITGI defines the SAP as "The framework documents a common and agreed level of IT risks, mitigation strategies and agreed-upon residual risks. Any potential impact on the goals of the organization caused by an unplanned event should be identified, analyzed and assessed. Risk mitigation strategies should be adopted to minimize residual risk to an accepted level. The result of the assessment should be understandable to the stakeholders and expressed in financial terms, to enable stakeholders to align risk to an acceptable level of tolerance."* As defined in ITIL/ISO27001,(4.1) - Information Security Management System - General Requirements: Our Services: * IT Governance Institute 2006, "Control Objectives for Information and related Technology, 4th Edition" - Cobit 4.0, Plan and Organize - Assess and Manage IT Risks (PO.09) |
Recent Blog Post
Questions?
For information and help - contact us.
Company Overview
|
||
|
© 2006-2012 Control Origins. All Rights Reserved
Terms of Use | Privacy Policy A Web Project Mechanics Production |
||||