search

MAN.7 Cybersecurity Risk Management

# PROCESS PURPOSE 
The purpose is to regularly identify, analyze, prioritize, and monitor risks of damage to relevant stakeholders.

# PROCESS OUTCOMES 
  • O1 The is defined including its functions and boundaries.
  • O2 Relevant , threats and are identified and regularly updated.
  • O3 Cybersecurity risks are analyzed based on impact rating and rating in order to support prioritization for the treatment of risks.
  • O4 The status of risk and the progress of the risk treatment activities is determined.
  • O5 Appropriate treatment is taken to mitigate the impact of risk based on its priority, likelihood, and consequence or other defined risk threshold.

# BASE PRACTICES 
BP1 Identify cybersecurity risk management scope. ( O1, O2 )
BP2 Identify cybersecurity events. ( O2 )
BP3 Analyze risks. ( O3 )
BP4 Define risk treatment options. ( O4, O5 )
BP5 Define and perform risk treatment activities. ( O4, O5 )
BP6 Monitor risks. ( O4 )
BP7 Take corrective action. ( O5 )

# OUTPUT INFORMATION ITEMS 
15-51 Analysis results ( O1, O2, O3 )
14-02 Corrective action ( O4, O5 )
17-53 Cybersecurity threat scenario ( O2 )
15-09 Risk status ( O4, O5 )
08-55 Risk treatment ( O3, O4, O5 )