Canada ITSP.10.033 Security and Privacy Controls and Assurance Activities Catalogue
RA: Risk assessment – Canada ITSP.10.033 Security and Privacy Controls and Assurance Activities Catalogue

Canada ITSP.10.033 Security and Privacy Controls and Assurance Activities Catalogue RA-03: RA-03 Risk assessment

The organisation conducts a risk assessment identifying threats and vulnerabilities, the likelihood and magnitude of harm from unauthorized access, use, disclosure, disruption, modification or destruction, and the likelihood and impact of adverse effects on individuals from handling personal information; integrates organisation and business-level risk results with system assessments; documents results in the plans or a report; reviews and disseminates them; and updates the assessment at a set frequency or on significant change. The GC discussion adds human, signals and imagery intelligence to all-source intelligence. 4 enhancements.

Maintained by Gerard Blokdyk

Other controls in RA: Risk assessment – Canada ITSP.10.033 Security and Privacy Controls and Assurance Activities Catalogue

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.