Risk assessment
Risk assessment forms part of our information security management system. The process considers assets, threats and vulnerabilities, assesses likelihood and impact, and records risk owners and treatment decisions.
A full assessment is required annually, with reassessment after significant changes and assessment at the start of sensitive-data projects. This helps connect the changing platform and organisation with the security priorities that need attention.
- Identify the information and services a risk could affect.
- Assess likelihood and impact to support prioritisation.
- Record ownership, treatment and the reasons behind risk decisions.
