SRA Instructions
Step-by-step instructions to help you conduct a Security Risk Assessment (SRA).
Overview
The steps of the SRA process are:
Context Assessment (i.e., understand the big picture).
Identify and list the specific threats in the operational area.
Describe each threat.
For each threat, list the vulnerabilities and existing mitigation measures.
Assess the likelihood and impact of each threat to the organisation (based on the above).
Plot the threats according to their risk level (likelihood x impact) in the risk matrix.
Identify (additional) mitigation measures that are needed (to reduce the risk if necessary)
Complete the Security Risk Register (SRR).
The steps are explained in more detail below.