Guideline 2003/7 Guide on risk assessment to promote information security in central government

Description

In central government organisations, risk management and assessment must be carried out in a systematic and comprehensive manner so that the perspectives and security needs of different functions are covered. Risk management and assessment shall also include preparing for serious incidents and emergency conditions as defined in the Emergency Powers Act (1080/1999). The guidelines provide tools and means for assessing information risks. The guide also describes the legal risk management obligations, the significance and organisation of risk assessment, and the means of risk management, the identification of threats, the assessment of the magnitude of risks, the definition of measures and further development. Risk assessment methods may include the methods described in Chapter 3 of the Guide, as well as the checklists of several VAHTI guidelines. An appendix to the instructions contains a checklist to identify security threats. It is particularly important, based on analyses of the probability and severity of the threat, to identify the most significant and urgent risks. (18.10.2011)

Resources

Name Format Description Link
0 https://www.avoindata.fi/data/dataset/1c1c372d-b8cd-4af3-8a56-50a714580667/resource/319866d0-8770-4c93-9951-8b1020808551

Tags

  • yhteentoimivuus

Topics

Categories