Once the risk assessment has been completed, the next step is to decide what actions to take to address the resulting risks. In this step, the cybersecurity team decides, in accordance with ISO/SAE 21434 and corporate policy, whether the risks can be avoided, reduced, shared, or accepted. Each individual risk that is greater than a minimum value must be analyzed. If cybersecurity controls are applied to reduce the risks, the new risk values are calculated. In this step of TARA, cybersecurity claims and cybersecurity goals are defined when risks are accepted or shared, or when cybersecurity controls are applied. We continue with our case studies and provide examples of various risk treatment decisions, including the mapping of cybersecurity controls. Although this is the final formal step of the TARA, we describe how the TARA is actually an evolving document, and the process can be iterated as often as needed.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Risk Treatment Decision

  • Rodrigo do Carmo,
  • Alexander Schlensog

摘要

Once the risk assessment has been completed, the next step is to decide what actions to take to address the resulting risks. In this step, the cybersecurity team decides, in accordance with ISO/SAE 21434 and corporate policy, whether the risks can be avoided, reduced, shared, or accepted. Each individual risk that is greater than a minimum value must be analyzed. If cybersecurity controls are applied to reduce the risks, the new risk values are calculated. In this step of TARA, cybersecurity claims and cybersecurity goals are defined when risks are accepted or shared, or when cybersecurity controls are applied. We continue with our case studies and provide examples of various risk treatment decisions, including the mapping of cybersecurity controls. Although this is the final formal step of the TARA, we describe how the TARA is actually an evolving document, and the process can be iterated as often as needed.