
Risk Management ◾ 73
check is what you want to instill in this process. In the 30 years I have been in infor-
mation security, this threat has always made every discussion list. I am not certain
that I can cite one example of this threat actually occurring.
So when you discuss probability, you will want them to address if this threat
has actually occurred. If so, when was the last time that the threat did occur? is
will provide the team with an ongoing reality check. You will want to keep them
focused on the fact that the threats are being examined with existing controls in
place.
Once the probability has been established, you will want to iden ...