Consensus Policy Resource CommunityRisk Assessment PolicyFree Use Disclaimer: This policy was created by or for the SANS Institute for theInternet community. All or parts of this policy can be freely used for your organization.There is no prior approval required. If you would like to contribute a new policy orupdated version of this policy, please send email to policy-resources@sans.org.Things to Consider: Please consult the Things to Consider FAQ for additionalguidelines and suggestions for personalizing the SANS policies for your organization.Last Update Status: Retired1. OverviewSee Purpose.2. PurposeTo empower Infosec to perform periodic information security risk assessments (RAs) for thepurpose of determining areas of vulnerability, and to initiate appropriate remediation.3. ScopeRisk assessments can be conducted on any entity within or any outside entitythat has signed a Third Party Agreement with . RAs can be conducted on anyinformation system, to include applications, servers, and networks, and any process or procedureby which these systems are administered and/or maintained.4. PolicyThe execution, development and implementation of remediation programs is the jointresponsibility of Infosec and the department responsible for the system area being assessed.Employees are expected to cooperate fully with any RA being conducted on systems for whichthey are held accountable. Employees are further expected to work with the Infosec RiskAssessment Team in the development of a remediation plan.For additional information, go to the Risk Assessment Process.5. Policy Compliance5.1 Compliance MeasurementThe Infosec team will verify compliance to this policy through various methods, including butnot limited to, business tool reports, internal and external audits, and feedback to the policyowner.5.2 ExceptionsAny exception to the policy must be approved by the Infosec team in advance. SANS Institute 2013 – All Rights Reserved Page 2Consensus Policy Resource Community5.3 Non-ComplianceAn employee found to have violated this policy may be subject to disciplinary action, up to andincluding termination of employment.6 Related Standards, Policies and Processes• Risk Assessment Process• Third Party Agreement7 Definitions and TermsNone.8 Revision HistoryDate of Change Responsible Summary of ChangeDec 2013 SANS Policy Team Converted to new format and retired
đang được dịch, vui lòng đợi..
