Risk Mitigation Worksheet Template

Reviews
Shared by: ocak
Stats
views:
1686
rating:
not rated
reviews:
0
posted:
1/28/2008
language:
English
pages:
0
CDC Risk Assessment ReportRevision 08-16-05 Appendix D Risk Mitigation Worksheet for Date Completed: , 2005 Date Last Modified: , 2005 Certifying Authority Signature: Date: Sensitive But Unclassified 1 CDC Risk Assessment ReportRevision 08-16-05 Appendix D Risk # 1 Rank (High/Moderate/Low) Moderate EAAL Transaction # N/A EAAL Risk Description (1,2,3,4) N/A (RA-2) Lack of data classification and management. Proposed Alternatives Response/Comments Will use FIPS-199 as guidance. Will use FIPS-199 and NIST 800-30 as guidance Recommended Controls Conduct a data sensitivity assessment. Establish a level of security for all agency information systems commensurate with the sensitivity of the information and the risk and magnitude of loss or harm that could result from improper operation of the information system, as mandated by FIPS 199. Selected Y/N Y Y POAM Tracking Number _ (POA&M Quarter A,B,C,D)_ Year _1 (Example: ABC_A_2006_1) Recommendation That Risk Be Accepted As Mitigated Certifying Authority Initials: CA Comments: Sensitive But Unclassified 2 CDC Risk Assessment ReportRevision 08-16-05 Appendix D Risk # 2 Rank (High/Moderate/Low) Moderate EAAL Transaction # N/A Selected Y/N N EAAL Risk Description (1,2,3,4) N/A (PS-7) Lack of policy and procedures for outsourcing. Proposed Alternatives Response/Comments This is an Enterprise issue for personnel security. Recommended Controls Develop and promulgate policy and procedures for outsourcing. POAM Tracking Number N/A Recommendation That Risk Be Accepted As Mitigated Certifying Authority Initials: CA Comments: Sensitive But Unclassified 3 CDC Risk Assessment ReportRevision 08-16-05 Appendix D Risk # 3 Rank (High/Moderate/Low) Moderate EAAL Transaction # 2 EAAL Risk Description (1,2,3,4) 2 (AC-17) VPN/Keyfob access does not meet EAAL Level 4 (NIST 800-63) requirements. Proposed Alternatives Response/Comments Recommended Controls Migrate all remote authentication roles to CDC secure data network (SDN) or to another mechanism approved by the OCISO. Selected Y/N POAM Tracking Number _ (POA&M Quarter A,B,C,D)_ Year _1 (Example: ABC_A_2006_1) Recommendation That Risk Be Accepted As Mitigated Certifying Authority Initials: CA Comments: Sensitive But Unclassified 4

Related docs
Risk Mitigation Worksheet Template
Views: 3  |  Downloads: 1
Mitigation Best Practice Submission Worksheet
Views: 34  |  Downloads: 3
Template Mitigation Banking Instrument
Views: 25  |  Downloads: 1
Template Mitigation Banking Instrument
Views: 30  |  Downloads: 0
Risk Management Template
Views: 6  |  Downloads: 4
Risk Template
Views: 212  |  Downloads: 33
IT Risk Assessment
Views: 21  |  Downloads: 6
Risk Management Plan Template
Views: 587  |  Downloads: 131
Contingency Risk Analysis
Views: 1180  |  Downloads: 224
premium docs
Other docs by ocak
Template Project Scale[1]
Views: 4320  |  Downloads: 674
Strategic Asset Plans[1]
Views: 2394  |  Downloads: 539
Steering Committee Charter template[1]
Views: 5214  |  Downloads: 663
Status Report Management Process Flow example[1]
Views: 4988  |  Downloads: 1086
Status Report Example
Views: 7630  |  Downloads: 1777
Scope Statement Development Instructions[1]
Views: 2174  |  Downloads: 92
Schedule Of Excess Risks[1]
Views: 1012  |  Downloads: 32
Risk Value Assessment Tool
Views: 1804  |  Downloads: 146
Risk Response Plan
Views: 1239  |  Downloads: 57
Risk Model Template Tool instructions
Views: 613  |  Downloads: 34
Risk Matrix
Views: 1244  |  Downloads: 79
Risk Management Work Breakdown Structure
Views: 1367  |  Downloads: 171
Risk Management Toolkit
Views: 736  |  Downloads: 156