
353
Appendix A: Facilitated
Risk Analysis and
Assessment Process
(FRAAP)
Company
Information
Security
Analyst
(ISA)
With the Company Owner, establish the Risk Assessment Scope
statement and enter the approved statement in the appropriate
location on the Risk Assessment Process Form (included at back
of procedure)
Provide the current Risk Assessment Threat Chart (included at
back of procedure)
Company
Owner
(Unit or
Department
Director)
Using the Risk Assessment Threat Chart, identify how likely the
threat is to occur during the next 12 months. Select the most
appropriate of four choices: probable, moderate, rare, not
applicable (see Likelihood T