Process for Assessing Risk

Assessing risk is a process and as such, is something that must be periodically repeated. It’s really not much different from the automated patch-management tools you are probably using. True security requires ongoing effort. There is never a wrong time to assess risk and examine network vulnerabilities. There are three key points at which assessments should be considered:

  1. When a new program is developed, a risk analysis should be performed to establish the security state of the system. An analysis performed early on like this helps establish whether security problems exist. This is beneficial when new code or applications are developed for which problems can be found and fixed early on.

  2. An analysis of risk should be ...

Get Inside Network Security Assessment: Guarding Your IT Infrastructure now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.