Your organization needs to have defined processes in place for completing risk treatment and risk mitigation activities once a risk assessment has been completed. Without these processes in place, risks may be identified during risk assessments but never properly addressed and managed. Treatment and mitigation requirements need to be assigned to clearly defined owners. This helps to ensure that appropriate personnel are held accountable for addressing identified risks in a reasonable timeframe. If not, your organization may fall victim to one of the worst types of risk – one of which you are aware of but do nothing to resolve.
Risk treatment and risk mitigation actions should be prioritized based on the business importance or criticality of impacted systems, probability of risk impact, financial impact, reputational impact, or legal impact. The risk treatment process should determine all activities that are necessary to address or mitigate risks. This process should result in a documented risk treatment plan. Once a risk treatment plan is developed, appropriate risk mitigation should occur to ensure that identified risks are effectively managed.
The risk tolerance of your organization will influence risk treatment decisions and actions. Your risk treatment process should include the need to determine an appropriate response to risk before generating a plan of action. Overall risk treatment and mitigation decisions should include performing a cost-benefit analysis of any planned remediation activities or the implementation of countermeasures.
Risk treatment is generally performed in one of the following ways:
Limit the number of risks that are “accepted” by your organization. Accepting too many risks will eventually defeat the purpose of having a risk management program in place by leaving your organization susceptible to threats versus addressing them properly.
The criteria to be used to determine whether an identified risk will be avoided, reduced, transferred, monitored, or accepted should be defined and documented. Regardless of how risks are managed, risk treatment requires careful planning, monitoring, and oversight. Executives, risk management teams, and other stakeholders should be involved in reviewing and acknowledging risk treatment decisions to ensure transparency as well as ongoing support for the process. More than any other area of risk management, assigning risk treatment requires effective and continual communication to drive stakeholder interaction and engagement in the process. Your treatment process should include the following activities:
A core principle of enterprise risk management is that not all risks can be removed for your organization or any organization. Regardless of risk treatment and mitigation efforts, some level of residual risk will remain. The changing dynamics of the threat and risk environment require ongoing monitoring. The status of any residual risk should be tracked and monitored as your organization’s objectives, risk tolerance, threats, and business operations continue to evolve. If residual risk is not adequately monitored, what is a low priority today can evolve into tomorrow’s risk management failure.
Risk mitigation is the process of implementing specific controls to reduce risk. The effectiveness of these controls should be evaluated to ensure they protect against the identified threats or vulnerabilities as intended. Evaluation of these controls can be accomplished with tools that supplement and complement assessment or audit activities. Two examples of these tools are control self-assessments and scenario analysis:
Additionally, the evaluation of mitigating controls should encompass external requirements, such as laws, regulations, and widely accepted control standards and practices. Failure to comply with external requirements, whether legal, regulatory, or contractual, can result in compliance risk as well as strategic, reputation, or other risks. Conformance with widely accepted control standards and practices can demonstrate due care in the operation of security controls and potentially reduce operational risk.
Conformance with external requirements alone is not sufficient to ensure that the overall process is adequate. The risk management process encompasses risk posed by business operations in your organization’s specific internal and external environment. Accordingly, the risk mitigation evaluation process should consider whether the controls used for mitigation, when combined with other controls included in the cybersecurity program, mitigate the risk as intended.
Look to Vistrada Cybersecurity experts for more information on assessing risks for any enterprise organization.