Initial Risk Analysis
To conduct a risk analysis for University of Houston information resources.
ScopeUniversity of Houston information assets, and any process, facility, or equipment associated with the creation, processing, and retention of the information.
StandardUniversity of Houston should conduct a risk assessment program consisting of the following phases:
- Identification of assets.
- Estimation of asset values.
- Identification of threats.
- Identification of vulnerabilities.
- Calculation of risk.
Factors to consider when conducting a risk analysis include:
- How to manage the risk analysis program.
- What methodology to use.
- What data collection methods to use.
- When risk analysis should be conducted.
- What is to be presented to top management.