Risk management strategy

Glesys applies structured risk management to identify, assess, prioritize, treat, and monitor risks that may impact network and information system security.

Key elements:

  • Enterprise risk governance: A consolidated Enterprise Risk Register and defined approach to evaluating impact/probability, prioritization, ownership, treatment and quarterly executive review.

  • Risk-based decision-making: Risk management is integrated with audits, BIAs, supplier assessments, incidents, and major changes.

  • Risk-aware change handling: Changes affecting systems, services or controls are recorded, assessed proportionally, approved at the right level, and reviewed after implementation.

Last updated

Was this helpful?