I want to confirm that this answer looks correct or if I am missing anything for
ID: 3742237 • Letter: I
Question
I want to confirm that this answer looks correct or if I am missing anything for Security Risk Managment Lab 6:
Question 10.) In your Lab Report file, describe the elements of an IT risk-mitigation plan outline by covering the following major topics:
Executive summary
Prioritization of identified risks, threats, and vulnerabilities organized into the seven domains
Critical “1” risks, threats, and vulnerabilities identified throughout the IT infrastructure
Short-term remediation steps for critical “1” risks, threats and vulnerabilities
Long-term remediation steps for major “2” and minor “3” risks, threats and vulnerabilities
Ongoing IT risk-mitigation steps for the seven domains of a typical IT infrastructure
Cost magnitude estimates for work effort and security solutions
Implementation plans for remediation
Executive Summary - Risk Mitigation plan is basically planning of securing projects from any sudden emergency and. in the IT risk mitigation plan one develops such options so that action can be taken for reducing any threat to enhancement of opportunities so that projects objective can met.
In this plan we need to monitor the potential threats for the project and track them regularly. This is done by management team in every project. They find the risk opportunities in everything and evaluate it on some certain conditions. So that in future if such risk will occur then a balanced action can be taken towards it.
In the Risk Mitigation step, it involves of the development plans designs so that one can manage or eliminate the risks to a desired level which will be acceptable. And once the Mitigation plan implemented, it's needing to be continuously monitored so that it can be revised as per the environment in the project.
Explanation / Answer
Dear Student,
The answer looks good. but to be a bang on you can add the below points as well :
The identified risks are prioritized based on its severity and the corresponding quick remedy is being noted. Also the potential thread is being analysed and a permanent fix is taken up so as to avoid the same in future. The prioritization of the risks are carried out based on the impact or the criticality of the issue being reported.
Happy Learning
Related Questions
drjack9650@gmail.com
Navigate
Integrity-first tutoring: explanations and feedback only — we do not complete graded work. Learn more.