00:01
Here, our risk management framework is a process that aims to manage the risks to an organization's information system.
00:10
This is a six -step process that includes categorization of the system, selection of security controls, implementations of the controls, assessment, authorization, and then continuous monitoring.
00:24
This is going to improve security over time by continuously identifying, assessing, and migrating risks.
00:35
It's also going to ensure that the controls are always up to date and effective against the latest threats.
00:48
For the categorization of our corporate network, we can use low, moderate, and high impact levels for confidentiality, integrity, and availability.
01:06
For example, if the loss of confidentiality could have a severe or catastrophic adverse effect, we would categorize that as a high impact, and so on and so forth...