> For the complete documentation index, see [llms.txt](https://docs.glesys.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.glesys.com/security/security-measures/risk-management-strategy.md).

# Risk management strategy

Glesys applies structured risk management to identify, assess, prioritize, treat, and monitor risks that may impact network and information system security.

### Key elements:

* **Enterprise risk governance:** A consolidated Enterprise Risk Register and defined approach to evaluating impact/probability, prioritization, ownership, treatment and quarterly executive review.
* **Risk-based decision-making:** Risk management is integrated with audits, BIAs, supplier assessments, incidents, and major changes.
* **Risk-aware change handling:** Changes affecting systems, services or controls are recorded, assessed proportionally, approved at the right level, and reviewed after implementation.
