90 likes | 303 Views
Information Security Risk Assessment. 1. Required by law and policyHIPAAGLBAPCI DSSFERPAState laws. IT Risk Assessments are Different. ERM COSOFocuses on internal controlsIT Security Risk Assessments NIST 800-30Focus on asset or system. NIST 800-30 Stages. STEP 1: SYSTEM CHARACTERIZ
E N D