Processes: Risk Management
No processes match the current filters.
Computerised System Risk Management Lifecycle
Risk Management
ID: P026
The end-to-end risk management process for computerised systems across all lifecycle stages as defined in sop031554. Covers identification, analysis, evaluation, control, and review of risks from initial implementation through retirement, aligned to ICH Q9.
Source Documents (1)
Mapped Citations (44)
- 16.14 Conduct Threat Modeling
- 3.7 Establish and Maintain a Data Classification Scheme
- 7.1 Establish and Maintain a Vulnerability Management Proces...
- AS.164.308.a1-i
- AS.164.308.a1-ii-a
- AS.164.308.a1-ii-b
- AS.164.308.a7-ii-e
- Application Software Security
- BCR-02 Risk Assessment and Impact Analysis
- CEK-07 Encryption Risk Management
- DL-2.D
- GRC-02 Risk Management Program
- GV.MT-P1
- GV.OC-01
- GV.OC-02
- GV.OC-05
- GV.OV-02
- GV.PO-P6
- GV.RM-01
- GV.RM-02
- GV.RM-03
- GV.RM-04
- GV.RM-06
- GV.RM-P1
- GV.RM-P2
- GV.SC-03
- ID.AM-05
- ID.DE-P1
- ID.RA-01
- ID.RA-03
- ID.RA-04
- ID.RA-05
- ID.RA-06
- ID.RA-P1
- ID.RA-P3
- Information security in project management
- OS-1.A.3
- OS-1.A.6
- OS-1.C
- Risk Management
- SS.164.306.a1
- SS.164.306.a2
- TVM-07 Vulnerability Identification
- Utilize a Risk-rating Process
Implementation Risk Assessment and Risk-Based Testing
Risk Management
ID: P050
A structured process defined in GD-0304839 for determining an appropriate risk-based test approach for computerised systems. The process involves identifying business process and technical risks, establishing a test strategy with test rigour commensurate to risk level, and executing and reporting on
Source Documents (1)
Mapped Citations (41)
- 16.13 Conduct Application Penetration Testing
- 16.14 Conduct Threat Modeling
- 18.1 Establish and Maintain a Penetration Testing Program
- 18.2 Perform Periodic External Penetration Tests
- 18.5 Perform Periodic Internal Penetration Tests
- AIS-05 Automated Application Security Testing
- AS.164.308.a1-ii-a
- AS.164.308.a1-ii-b
- AS.164.308.a7-ii-e
- Apply Static and Dynamic Code Analysis Tools
- BCR-02 Risk Assessment and Impact Analysis
- CCC-02 Quality Testing
- Change Testing
- Conduct Regular External and Internal Penetration Tests
- Create Test Bed for Elements Not Typically Tested in Product...
- Ensure Results from Penetration Test are Documented Using Op...
- Establish a Penetration Testing Program
- GV.RM-01
- GV.RM-06
- GV.RM-P1
- ID.IM-02
- ID.RA-01
- ID.RA-04
- ID.RA-05
- ID.RA-P4
- Include Tests for Presence of Unprotected System Information...
- Operational Checks
- Pre-Production Testing
- Protection of information systems during audit testing
- Qualified Test Environment
- Risk Management
- SS.164.306.a2
- Security testing in development and acceptance
- TVM-06 Penetration Testing
- TVM-07 Vulnerability Identification
- TVM-08 Vulnerability Prioritization
- Test Evidences
- Test information
- Testing Tools Validation
- Utilize a Risk-rating Process
- Validation Approach
Roles (5)