Write a Risk Statement That Can Be Treated
Create a treatable information security risk statement from a vague concern.
The team starts with the vague concern "API security" and needs a risk statement that can be scored and treated. Risk statement pattern: If threat event exploits vulnerability affecting asset, then business or information security impact could occur. The common trap is writing a topic or missing control as the risk. "No API gateway" may be a condition, but the risk is the unauthorized access, data change, outage, or compliance impact that could follow. Asset Name the asset or process: customer learning records exposed through platform APIs. The asset gives the risk business meaning and tells the team whose objective…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in