Skip to main content

3.2.1.2 Cyber Security Risk Analysis

No: 381000091275 Date(g): 24/5/2017 | Date(h): 28/8/1438 Status: In-Force

Principle

A cyber security risk analysis should be conducted based on the likelihood that the identified cyber security risks will occur and their resulting impact.

Objective

To analyze and determine the nature and the level of the identified cyber security risks.

Control considerations

  1. A cyber security risk analysis should be performed.
  2. The cyber security risk analysis should address the level of potential business impact and likelihood of cyber security threat events materializing.