Hello, my name is Constance Blanson, and in these lessons, you will learn IT risk management frameworks, compliance versus risk management, performing a risk assessment, the stages of a risk assessment, evaluating loss, assessing risk acceptability, and selecting control strategies to include transference, mitigation, acceptance, or termination. Let's get started. Before we can get into the discussion on risk management frameworks, we must identify just what is risk. Risk is the likelihood or even probability that something unexpected is going to occur. And this unexpected occurrence will either result in a gain or a loss to the organization. Within the world of information security, most organizations focus on ways to guard against asset losses. Companies often deploy risk management techniques, such as risk management frameworks. One example of a framework is the risk management framework, or RMF, from the National Institute of Standards and Technology, or NIST. The NIST RMF is an informative guide that organizations can use when implementing a risk management process. The RMF is a process that combines both security and risk management as part of the system development lifecycle and it follows seven steps. The seven steps of the risk management framework developed by NIST consists of the first step in preparation or preparing. What the organization does during this particular step or phase, it includes all of the activities that the organization will undertake to manage its security and to manage the risks that have been identified. The second step or phase within the RMF risk management framework is to categorize the system. When an organization takes this particular step, they are basically categorizing and prioritizing the assets within the organization. These assets have been identified to contain threats that could possibly lead to vulnerabilities that could lead to risk. Another step in the RMF, or risk management framework, is the selection step. In this particular step, the organization now will set up baselines. They will prioritize and put into categories the risk that have been identified against the assets within the organization. Another step within the RMF, or risk management framework, is implementation. Within this particular step or phase, the organization now will implement security controls. These security controls are aimed at mitigating any risk that have been identified. The next step is to access, access those security controls that have been implemented, making sure that they are appropriate to the extent that they are functioning, and also to make sure that the controls will provide the intended outcomes. The next step in the RMF risk management framework is authorization. The organization now is authorizing the system to utilize those security or mitigating controls that have been implemented and applied. And the last phase of the risk management framework is to now provide continual monitoring, focusing on those security controls, looking at the effectiveness of those controls and documenting any changes to the security or even to those assets, which risk have been identified. When organizations utilize a risk management framework, they are applying a discipline and structured approach to integrating some risk management strategies within their system development lifecycle. The use of a risk management framework is the continual improvement in identification of all threats, vulnerabilities and risks that can impact any asset within that organization. Thanks for watching our lesson on IT risk management frameworks.