You are here

Mitigating risks with management controls

8 September, 2015 - 16:42

Management controls include management activities related establishment of information system requirements and control processes intended to ensure that those requirements are met. Critical information assurance management controls include:

  1. Creation of policies, procedures, standards and training requirements directly relating to the improvement of information system confidentiality, integrity and availability.
  2. Performance of risk analyses to evaluate risk potential of new information systems and re-evaluate risks associated with existing business applications and IT infrastructure.
  3. Management of information system change

The following sections provide a general overview of each of these three important information assurance management controls.