Using the Results of the Risk Assessment
The results of risk assessments are used for a variety of security management functions. These results need to be evaluated in terms of the organization’s mission, risk tolerance, budgets and other resources, and cost of mitigation. Based on this evaluation, a mitigation strategy can be chosen for each risk and appropriate controls and countermeasures can be designed and implemented.
Risk assessment results can also be used to communicate the risk decisions and expectations of management throughout the organization through policies and procedures.
Finally, risk assessments can be used to identify areas where incident response capabilities need to be developed to quickly detect and respond to inherent or residual risk or where security controls cannot adequately address the threat.