How to Perform an Information Asset-Based Risk Assessment
Risk assessments are a required part of a financial institution's Information Security Program, but understanding how to perform one based on information assets is where many organizations get stuck. What counts as an information asset? How do you evaluate risk at the information asset level? And how does this connect to your Information Security Program?