From the course: ISACA Certified in Risk and Information Systems Control (CRISC) Cert Prep
Unlock this course with a free trial
Join today to access over 25,300 courses taught by industry experts.
Risk action plans
From the course: ISACA Certified in Risk and Information Systems Control (CRISC) Cert Prep
Risk action plans
- [Instructor] So once we identify, assess, and analyze the risk, we'll need to figure out which of the response options we want to take. So as we talked about, there is a lot of different internal and external factors we'll want to take a look at, as well as the risk analysis that we did. So, why is the risk going to be as frequent as we think it is and have the impact that we think it is? After we take a look at those, we'll take a look at our risk response options. I think as we look through those response options, pretty much anything should be on the table, right? The most expensive, the least expensive, risk acceptance, only risk mitigation. Taking a look at our insurance contracts, right? The options there are going to be endless. And then we want to prioritize those risk response options. Now, as we talked about on our decision slide, there's going to be a lot of different things that we want to weigh in…
Contents
-
-
-
-
-
-
(Locked)
Risk response options and selection8m 16s
-
(Locked)
Third-party risk and control8m 53s
-
(Locked)
Risk action plans3m 29s
-
(Locked)
Control standards, frameworks, and types of controls7m 6s
-
(Locked)
Control design and selection13m 30s
-
(Locked)
Control testing7m 30s
-
(Locked)
Data collection and reporting8m 44s
-
(Locked)
Metrics5m 46s
-
(Locked)
Monitoring, reporting and associated techniques9m 13s
-
(Locked)
Issues, findings and exceptions8m 14s
-
(Locked)
-
-