
•
Net risk analysis: The net operational risk includes the mit-
igating effects of existing controls that are in place, based
upon the control effectiveness in reducing threat likelihood
and impact loss. At this point, a risk model can be derived
to indicate the net risk associated with every business threat
and the gaps and omissions in control effectiveness.
•
Risk improvement selection: The operational risk model is
used to identify where the organization is exposed to unac-
ceptable levels of risk. New control options must be sub-
jected to:
•
– effectiveness assessment;
•
– implementation cost assessment;
•
– cost/benefit evaluation and prioritization based ...