To do List
Phase
Action Items
Check
Risk
Understand external/internal environment.
□
Evaluation
Identify threats to your organizations.
□
Raise all the risks regarding cyber security.
□
Establish risk evaluation criteria and method.
□
Evaluate impact of the risks.
□
Identify risks to be mitigated.
□
Establish evaluation criteria.
□
CII
Identification
Identify critical IT services for your national
□
security.
Usable
Estimate impact on critical IT services.
□
Identify IT services to be protected.
□
Create IT inventory list regarding the services.
□
Identify CII to be protected.
□
Estimate usable budget.
□
Resources
Estimate usable human resources (both in skills
□
Estimation
and numbers).
□
Estimate usable IT infrastructures.
□
Estimate possible external aids.
□
5