ABSTRACT

Risk assessment is not done to fulfill audit requirements. It is not done because information security mandated it. It is not done to be in compliance with laws and regulations. Risk assessment is done because it makes sound business sense and provides management with the documentation to prove that it has performed its due diligence.