
Risk Management ◾ 83
reat Existing Control Select New or Enhanced Control(s)
New
Probability/
Impact
New
Risk
Level
Acceptable
Level
(Yes/No)
Copies of reports could
be diverted (written or
electronically) to
unauthorized or
unintended persons
Information classification policy in
place. Information handling standards
are being developed
Information classification policy in
place. Information handling standards
are being developed
L/M Low Yes
Insecure e-mail could
contain confidential
information
Information handling standards are
being developed.
Concern to be addressed in GLBA’s
employee awareness program and new
employee orientation
Information handling ...