Safari Books Online is a digital library providing on-demand subscription access to thousands of learning resources.
Information security risks need to be managed on a formal basis and reviewed regularly to ensure that they are being managed in accordance with updates to the organisation’s business practices and updates to, or adoption of new, technologies.
A risk register should be created and all identified risks recorded. A risk treatment plan should also be developed outlining what controls are already in place, what additional controls need to be implemented and details of who is responsible for implementing and managing those controls.