Coffee & Compliance: Demystifying Risk Assessment

preview_player
Показать описание

An information security ("InfoSec") risk assessment is not only a security best practice but also necessary to meet the requirements of the ISO 27001, SOC 2, PCI DSS, and HIPAA compliance standards.

Chapters:
0:00 Welcome to Compliance Simplified
0:38 What is a Risk Assessment?
1:00 Why do you need a Risk Assessment?
2:20 What is the difference between a formal and informal Risk Assessment?
3:40 How to get started with a Risk Assessment
4:20 Can you fail a Risk Assessment?
8:25 What happens if I don't remediate a particular risk before my audit?
10:58 Can I accept a certain risk rather than remediating it?
13:10 Where should I start with my Risk Assessment?
14:30 How does the new approach to Risk Assessment vary from the traditional one?
Рекомендации по теме
Комментарии
Автор

Thanks a lot Matt and Eric for this wonderful session ! Risk assessment, Compliance and Security topics are well explained

kalpanasiddharth