Organizational risk
Every service should have a risk management plan to assess and manage risk. Risk management should be comprehensive to consider all hazards, including how the cloud service supports risk mitigation by design. This assessment is essential to make informed design decisions. Service risk must be contextualized as part of the broader organization risk strategy.
| GL-OPS-6: Do you have adequate people and process risk management systems in place covering a broad risk spectrum? |
|---|
-
Take an all-hazards approach: Include consideration of personnel, supply chain, cyber security, information security, and natural risks.
-
Have a strong understanding of controls that can be inherited from the cloud service provider, for example, the physical security of data centers.
-
Consider sovereign resilience requirements, which can aid in the survival of government in extreme circumstances.
-
Improvement plan – Document the preceding items into the relevant security documentation or concept of operations document.
-
-
Develop a risk management plan: Have a plan that supports ongoing risk assessment and treatment, and verifies that the service risk is contextualized as part of the organization’s risk profile.
-
Decide what matters most to your organization, and to your service. Considerations include social, cultural, political or regional issues, economic and technology trends, policy and law, and your organizations aims, policies and strategies.
-
Identify, analyze, and evaluate risks to help make sure that adequate treatments are identified so that your service is resilient.
-
When considering the risk of a service, consider whether the risk is acceptable for the associated service outcome it achieves.
-
Improvement plan – Document these items into the relevant security documentation or concept of operations document.
-
-
Align with required compliance frameworks: When implementing compliance frameworks such as CSA
, NIST , CISPE , ISM , and ISO , verify that the framework is appropriate for the risks requiring mitigation and that it is considered as part of the broader organizations risk strategy and risk appetite statement. -
Improvement plan – Document the preceding items into the relevant security documentation or concept of operations document, and provide relevant AWS certifications and risk management guides and case studies.
-
-
Determine the necessary conditions of engagement: Consider the Business Impact Level (BIL) of the service to determine personnel requirements, such as security clearances, vetting, data handling, and risk training.
-
Improvement plan – Document the preceding items into the relevant security documentation or concept of operations document, and provide the AWS certification programs as required.
-