RISK ASSESSMENT

Preparation

Understanding

Understanding

image4

  • Agree objectives, scope and parameters
  • Select assessment team
  • Develop assessment project plan

Understanding

Understanding

Understanding

image5

  • Information Gathering (Internal and external)
  • Review information and identify gaps and additional information requirements

Assessment

Understanding

Assessment

image6

  • Review methodology (Assessment structure, Grading systems, and Threat categorization)
  • Review drafts, identify gaps and anomalies
  • Follow up information gathering and consultation 

Reporting

Follow-up 1.

Assessment

image7

  • Draft risk report
  • Client review/risk workshop
  • Publish final report
  • Determine next step

Follow-up 1.

Follow-up 1.

Follow-up 1.

image8

  • Draft action plan with client
  • Assess progress
  • Report on progress

Follow-up 2.

Follow-up 1.

Follow-up 1.

image9

  • Assess progress
  • Report on progress