3.14 Risk Management Procedures and Documentation
Risk management is mostly achieved by combining administrative, technical and physical controls
Role of a risk practitioner is very critical to ensure that controls are adequate and operating as designed.
Risk practitioner should ensure that following control management procedure is followed:
Proper implementation of the control
Availability of documented procedures to support the operations
Availability of change management procedure for configuration
Training of the staff to review the controls
Allocate ownership of each control to senior official
(Practice Questions already covered in other topics)