Managing Risk with Policy
The risk management goals of our audit services are to:
- Identify risks along with recommendations to fix the problems.
- Use the identified risks as a basis for creating a policy, with the intent of preventing risks from becoming security events and liabilities.
Monitor for compliance to policy. Policy comes in many forms, including:
- Various types of security policy.
- Privacy policy.
- Compliance policy.
- Security plan.
- IT technical security policy.
- Promote the creation of a sustainable, ongoing corporate IT security process, which evolves under the auspices of governance.
- Encourage ongoing security training.
|