[{"data":1,"prerenderedAt":81},["ShallowReactive",2],{"content-query-o0R82IzBvV":3},{"_path":4,"_dir":5,"_draft":6,"_partial":6,"_locale":7,"title":8,"description":9,"head":10,"banner":27,"sides":34,"_id":76,"_type":77,"_source":78,"_file":79,"_stem":80,"_extension":77},"\u002Fservices\u002Fprocedural-services\u002Fenterprise-risk-assessment","procedural-services",false,"","Enterprise Risk Assessment - Cybermode","A Cybermode Enterprise Risk Assessment will identify, estimate, and prioritize cybersecurity risk to operations, assets, individuals, mission, and reputation.",{"meta":11,"link":23},[12,14,16,19,21],{"hid":13,"property":13,"content":8},"twitter:title",{"hid":15,"name":15,"content":9},"twitter:description",{"hid":17,"name":17,"content":18},"twitter:image","https:\u002F\u002Fcybermode.io\u002Fservices\u002Fprocedural-services\u002Fenterprise-risk-assessment\u002Fenterprise-risk-assessment-banner-lg.png",{"hid":20,"property":20,"content":8},"og:title",{"hid":22,"name":22,"content":18},"og:image",[24],{"rel":25,"href":26},"canonical","https:\u002F\u002Fcybermode.io\u002Fservices\u002Fprocedural-services\u002Fenterprise-risk-assessment",{"title":28,"desc":29,"img":30},"Enterprise Risk Assessment","A Risk Assessment is an evaluation of the \u003Cspan class=' font-weight-bold  text-primary'>procedural components of a company’s cybersecurity posture.\u003C\u002Fspan> It is the cornerstone of developing a \"Culture of Security\" within a company.",{"alt":31,"sm":32,"md":32,"lg":33},"enterprise risk assessment banner illustration",null,"\u002Fenterprise-risk-assessment-banner-lg.png",{"img":35,"text":37},{"alt":36,"sm":32,"md":32,"lg":33},"enterprise risk assessment illustration",[38,43,53,58],{"title":39,"content":40},"Quantitative or Qualitative",[41],{"content":42},"A Risk Assessment is a \u003Cb>quantitative or qualitative estimation\u003C\u002Fb> of risk related to an organization’s assets and the threats they face. A Risk Assessment first identifies an organization’s assets, then determines the threats to those assets. From this information, a control or mitigation is designed to minimize or remove the risk. The resulting value is residual risk.",{"title":44,"content":45},"Cybermode Enterprise Risk Assessment",[46,48],{"content":47},"A Cybermode Enterprise Risk Assessment will \u003Cb>identify, estimate, and prioritize risk to organizational operations, organizational assets, individuals, mission, functions, and reputation,\u003C\u002Fb> resulting from the operation and use of information systems. The Enterprise Risk Assessment by Cybermode \u003Cb>covers all three tiers in the risk management hierarchy: organization level, mission\u002Fbusiness process level and information system level.\u003C\u002Fb> The methodology is based upon the following accepted standards:",{"content":49},[50,51,52],"NIST SP 800-171","NIST SP 800-53","ISO\u002FIEC 27002:2013",{"title":54,"content":55},"Companies Always Own Their Risk",[56],{"content":57},"A business can transfer risk, reduce risk, or defer risk, but one thing is always true: \u003Cb>a business always owns its risk.\u003C\u002Fb> There will always be risk; the goal is to maintain it at an acceptable level.",{"title":59,"content":60},"Purpose of a Risk Assessment",[61,63,69,71,74],{"content":62},"The purpose of risk assessments is to inform IT management and develop risk responses by identifying:",{"content":64},[65,66,67,68],"The current threats to companies","The current threats directed through companies against other companies (i.e., vendors).","The impact or harm to companies that may occur given the potential for threats to exploit vulnerabilities.","The likelihood that harm will occur.",{"content":70},"\u003Cb>Every business with a sizable IT footprint should perform one.\u003C\u002Fb> It provides an excellent starting point from which to strengthen an organization's security posture. It identifies assets, outlines the threats against them, and generates a mitigation plan for the threats. A Risk Assessment focuses an organization's resources effectively to improve its cybersecurity posture.",{"content":72,"class":73},"Performing an Enterprise Risk Assessment along with a Comprehensive Penetration Test from Cybermode is an excellent way to cover both the technical and procedural components of cybersecurity.","text-primary text-italic",{"content":75},"It's impossible to eliminate all risk, but if an organization reduces its risk exposure each year, the probability that an adverse event will occur is very low.","content:services:procedural-services:enterprise-risk-assessment.json","json","content","services\u002Fprocedural-services\u002Fenterprise-risk-assessment.json","services\u002Fprocedural-services\u002Fenterprise-risk-assessment",1786216862374]