Risk-management-Identify-if-the-risk-will-be-avoided-and-the-plan-for-avoidance
Example doc is attached.
Students will be presented with several risks of various impacts (published in BB). Each student will have to develop a risk response plan for each risk.
Students should be sure to:
- Identify if the risk will be avoided and the plan for avoidance.
- Identify if the risk will be mitigated and the plan on how it will be mitigated.
- Identify if the risk will be accepted and the reason why the risk will be accepted.
- Identify if the risk will be transferred and how that risk will be transferred.
- Identify any residual risks once the plan is implemented.
- Include any impacts to the organization (budget, cultural, etc).
With the mess of the post / file not showing, I decided to change the assignment into a single scenario with two separate risks that need to be addressed. Please see attached for the scenario. I selected a pretty common scenario you might see in security. I’ve given you the SLE, ARO, etc…to help make a decision. Feel free to make additional assumptions if needed, and explain those assumptions in your response.

