Posts

Showing posts with the label security

Map risks and develop a security policy

 Then, it is necessary to map the security risks that the company has. The mapping needs to be very well executed, identifying the possible risks to reduce the impacts that they may generate. The process needs to be carried out by an information technology professional who has theoretical knowledge in the area, guided by the ABNT NBR ISO / IEC27005: 2008 Standard. That said, know four steps that should be considered when mapping risks: Diagnosis and classification of risks The first step is to know and classify the levels of risks: the context, whether they are associated with governance problems , lack of resources and failures in the system and infrastructure. 2. Risk analysis After mapping and cataloging the risks, it is necessary to assess the probability of incidents and the level of impact that will be caused in the company, classifying and prioritizing risks, to carry out tests and preventive measures against security incidents. 3. Action plan The third step involves creatin...