Security measures #
Lens and screen #
Measures reduce likelihood or impact. The form includes name, description, type, category, effectiveness, deployment and status.
Life cycle #
Risk manager creates and maintains. Effectiveness expressed as a percentage must be supported and reviewed; the status does not replace a control test. Before deletion, check related risks, actions and requirements.
Relationships #
Existing metrics contribute to the current/residual score. They can be linked to an action, to a line of SoA, to requirements and to an effectiveness test.
Description of fields #
The type and category describe the nature of the control. Effectiveness (%) expresses the estimated effect and must be proven. Deployment describes actual progress; the status allows monitoring of the life cycle.
Complete procedure #
Create a measure with a verifiable objective, choose type and category, document its deployment, then assign conservative effectiveness. Link it to risks and requirements, and plan a design or operational effectiveness test.
Example #
“MFA of privileged accounts”: preventive control, partial deployment, initial effectiveness justified by the coverage rate. An action carries the rest of the deployment.
Errors and best practices #
Do not confuse planned control with operational control. A high percentage without evidence distorts the current risk. After a failed test, reassess effectiveness, risks and associated actions.