From the course: CompTIA Security+ (SY0-601) Cert Prep: 10 Governance, Risk, and Compliance

Unlock the full course today

Join today to access over 22,600 courses taught by industry experts or purchase this course individually.

Ongoing risk management

Ongoing risk management

- [Instructor] Implementing security controls is only the beginning of the risk management journey. Security professionals must perform a variety of ongoing activities to ensure that risks remain properly managed. These include monitoring and assessing controls, measuring control effectiveness, reporting, and continuous improvement. Risk control assessments represent a point in time analysis of the risks facing an organization and the ability of controls to manage those risks properly. These assessments may be completed as self-assessments by an internal security team or as external assessments by a consultant or auditor. The risk environment changes on a regular basis and organizations should routinely review those risk assessments and perform periodic control assessments designed to test the correct functioning and effectiveness of their security controls. For example, most organizations use a firewall to block unwanted…

Contents