protecting that organisation’s part of cyberspace against threats. The team should approve security goals, policy, assign security roles and co-ordinate and review the implementation of cybersecurity across the organisation. The head of the team is accountable for its success. The executive may delegate this responsibility to heads of department, contractors and individual employees. The multi-disciplinary cybersecurity team coordinates action on shared risks and sets mandatory requirements for all stakeholders. Departmental heads are responsible for determining the additional level of compliance required and convincing the central body that the interpretation is competent. The organisation should have access to specialist cybersecurity advice. The team should develop contacts with external cybersecurity specialists or groups including relevant national authorities and, where appropriate, regional and global organisations. 16.1.2.1.2 Risk Management Every organisation faces internal and external factors that bring a degree of uncertainty to whether or not they will achieve its objectives. ISO 31000 regards this uncertainty as risk. Organisations manage risk by identifying it, analysing it, evaluating the likelihood of occurrence, determining the potential impacts of the risk materialisation and designing countermeasures. Organisations should decide whether to modify the risk by treatment to satisfy the risk criteria (ISO 2009). Similarly, ITU-T regards risk management as about assessing and quantifying risk and taking action to ensure that residual risk is below predetermined acceptable levels (ITU 2009f). Recommendation ITU-T X.1055 describes and recommends the processes, techniques and functional profiles for telecommunication information security risk management (ITU 2008c). Among other aspects, the risk management process provides guidance on how to:  Identify risks;  Analyse and evaluate the risks;  Identify and evaluate options for the treatment of risks; and  Select control objectives and controls for the treatment of risks. This Guide recommends that all organisations adopt solid risk management processes. Risk management process helps organisations determine what assets need protection, the threats they require protection against and the controls. The evaluation helps categorise risks by severity and involves making cost-effective decisions on what needs protection. The process helps organisations ensure that the efforts and money spent on security yield cost effective benefits (IETF 1997). Good risk management processes are not prescriptive. Instead, the processes recognise that organisations have different business requirements, structures and operational environments. The process defines broad requirements allowing organisations to decide the most cost effective and efficient risk management approaches (ISO/IEC 2008). A full treatment of risk management is outside the scope of this document. ISO/IEC 27005 is the definitive standard on the topic as it covers concepts such as context establishment, risk assessment, risk treatment, risk acceptance, risk communication and risk monitoring and review. ISO/IEC 27005 adopts the PDCA model. 16.1.2.1.2.1 Risk Assessment Model A risk assessment exercise helps your organisation to produce a list of risks that assets are facing or is likely to face (ITU 2008c). Thereafter, you should prioritise the risks to ensure that the more serious one get first attention. Serious risks are the type where the 76

Select target paragraph3