From the course: ISC2 Systems Security Certified Practitioner (SSCP) (2024) Cert Prep

Unlock this course with a free trial

Join today to access over 24,900 courses taught by industry experts.

Ongoing risk management

Ongoing risk management

- [Presenter] Implementing security controls is only the beginning of the risk management journey. Security professionals must perform a variety of ongoing activities to ensure that risks remain properly managed. These include monitoring and assessing controls, measuring control effectiveness, reporting and continuous improvement. Risk control assessments represent a point in time analysis of the risks facing an organization and the ability of controls to manage those risks properly. These assessments may be completed as self-assessments by an internal security team, or as external assessments by a consultant or auditor. The risk environment changes on a regular basis. An organization should routinely review those risk assessments and perform periodic control assessments designed to test the correct functioning and effectiveness of their security controls. For example, most organizations use a firewall to block unwanted…

Contents