Risk Management What is the Risk Assessment Process ? Step 1: Prepare for Assessment Step 2: Conduct a. Identify threat sources & events Assessment b. Identify vulnerabilities & predisposing conditions c. Determine likelihood of occurrence d. Determine magnitude of impact e. Determine Risk Step 3: Communicate Results Step 4: Maintain Assessment What are the MUST KNOW RISK TYPES ? o o o o o o External Internal Legacy systems Multiparty IP theft Software compliance/ licensing What are the MUST KNOW RISK MANAGEMENT STRATEGIES? Accept Avoid Transfer Cybersecurity Insurance o Mitigate o o o o