Risk Assessment Services mapped to Industry Standards
ITG Consulting Services uses an established and comprehensive approach to supporting its Customer’s information security initiatives by conducting risk assessment. Furthermore, our methodology and practice are directly mapped to industry standards and best practices for risk management; including ISO 31000, the NIST Risk Management Framework, the PMBOK, as well as FMEA.
ITG Consulting Services group consists of skilled risk assessment professionals with implementation, as well as day-to-day management experience of information security and management system environments. Our cliental includes Fortune 500 corporations, as well as both small and large government contractors.
Risk Assessment Methodology
Our methodology and approach is to identify scope and assessment boundaries, categorize potential hazards, risks, opportunities, and vulnerabilities. We determine what could impact the confidentiality, integrity, or availability of information related to the following key security concerns:
- Strategic mission,
- Business operations,
- Technical architecture and capabilities,
- Supplier interface, and
- Physical and environmental infrastructure.
Risk Assessment Procedure
Firstly, ITG works with each one of our customers to conduct an initial assessment of the business impact and likelihood of security failures to define risk level(s). Our team’s assessment approach focuses on:
- The probability of exploitation and compromise,
- Impact to the organization and its assets, and
- Ability to detect potential threats and/or risks.
These key areas determine an organization’s ability to respond to a security event, while plays a significant role in reducing the impact.
Secondly, based on our assessment and analysis practice, the Consulting Services group works directly with each Customer to assign risk priority, identify and evaluate options for treatment, and the application of appropriate controls to eliminate or mitigate the risk. We work with our customer to:
- Assign risk ownership, priority,
- Develop treatment and mitigation actions (steps to prevent the risk or circumstance from occurring), and/or
- Develop contingency plans for risks that meet certain thresholds (actions to minimize the effect of the risk or circumstance if it does occur).
Thirdly, after completion of the risk assessment and prioritization initiative, the Consulting Services team continues to support stakeholders’ and their involvement. Our approach focuses on:
- Response implementation
Finally, the Consulting Services group continues to work with our customers in the management of identified risks through monitoring, communication, and documentation. Mitigation plans and treatment plans are implemented, as appropriate, to control and manage risks effectively. Consequently, ITG customizes the recommended response plans based on risk priority, industry type, information classification, and the level of risk appetite of each customer. Additionally, we assess compliance requirements and how effective and to what degree risk treatment reduces the risk, taking into consideration the financial and resource commitments necessary to minimize the risk level.