A.3. Risks and Mitigation Plans for Critical Assets

As a result of conducting the OCTAVE Method, we identified five assets that are critical to the survival and success of MedSite. We then defined the risks to these assets and developed mitigation plans to address these risks. The assets we identified as being the most critical, and our rationale for selecting them, are listed in Table A-3.

For each critical asset, we provide the following information in this report:

  • Security requirements

  • Areas of concern

    Table A-3. MedSite's Critical Assets
    Critical AssetRationale for Selection
    Paper medical recordsNumber one documentation source
    Personal computersAlmost complete worker dependency on PCs, the workstations everyone uses to access the information assets ...

Get Managing Information Security Risks: The OCTAVESM Approach now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.