What is the ITSRB approach? The ITSRB approach is a
proactive and dynamic method that aims to ensure that IT
security risk is holistically managed, more effectively. In
principle, the ITSRB anticipates to reduce the risks associated
with confidentiality, integrity and availability of information
and IT.
Why is the ITSRB approach defined?: The motivation
behind defming the ITSRB approach was to formulate a method which would assist in managing IT security risk
thereby guaranteeing that relevant risk is addressed with
adequate and effective controls, at the right time.
How will the ITSRB approach achieve its goal?: The
ITSRB approach uses a combination of best practice IT
security risk management frameworks and the threat modeling
processes to ensure that risk emanating from both known and
unknown threats in the IT environment is managed.
When is the ITSRB approach going to be applied?: A
pragmatic tactic will be used when applying the ITSRB
approach in order for it to add value. This is because the
ITSRB uses a risk based approach; therefore its application
will be guided by the nature of the risk.
Where will the ITSRB approach be applied?: The ITSRB
approach will be applied within the IT environment of an
organisation.
Who will use the ITSRB approach?: IT security
professionals within any organisation can use the ITSRB
approach.