Around these building blocks a comprehensive process model is built for IT risk management that will look familiar to users of COBIT and Val IT4. Substantial guidance is provided on the key activities within each process, responsibilities for the process, and information flows between processes and performance management of the process. The process model is divided into three domains—Risk Governance, Risk Evaluation and Risk Response—each containing three processes:
-Risk Governance
-RG1 Establish and maintain a common risk view
-RG2 Integrate with ERM
-RG3 Make risk-aware business decisions
-Risk Evaluation
-RE1 Collect data
-RE2 Analyse risk
-RE3 Maintain risk profile
-Risk Response
-RR1 Articulate risk
-RR2 Manage risk
-RR3 React to events