Cyber risks are identified, at least in an ad hoc manner
Context and Guidance: Identification of cyber risks is a foundational risk management activity. It requires the organisation to identify the types of threats, vulnerabilities, and disruptive events that can pose risk to the operational capacity of assets and services. Identified risks form a baseline from which a continuous risk management process can be established and managed.
Related Practices • Progression: This practice is part of a practice progression. Practice progressions are groups of related practices that represent increasingly complete or more advanced implementations of an activity. The practices in this progression include: RISK-2a, RISK-2b, RISK-2c, RISK-2g, RISK-2h, RISK-2i, RISK-2j, RISK-2k, RISK-2l, RISK-2m.