Cyber risks are prioritized based on estimated impact, at least in an ad hoc manner
Potential impact to the organization of identified risks should be evaluated and used to prioritize cyber risks. A higher priority cyber risk should receive greater attention when determining potential mitigations or responses. Prioritization should focus on criteria deemed important to the enterprise such as safety impacts, operational impacts, and financial impacts (e.g., cost of recovery, potential cost of downtime or lost data). Prioritization may use qualitative methods to indicate relative impact level (e.g., High, Medium, Low).
Related Practices · Progression: This practice is part of a practice progression. Practice progressions are groups of related practices that represent increasingly complete or more advanced implementations of an activity. The practices in this progression include: RISK-3a, RISK-3b.