Hi,
I am a new user on Governacne & Compliance Manager. We are considering following two approaches to standardize our regular risk assessments.
1. Collect asset information against each risk assessment activity and add risks, threats and vulnerabilities against each risk assessment every time and evaluate control effectiveness. In this approach risks, assets, and vulnerabilities might have duplications, but we can start with tiny steps.
2. Collect complete asset inventory, potential risks, threats and vulnerabilities and upload into the system. For each risk assessment we can select associated assets, risks, threats and vulnerabilities from already uploaded data and evaluate control effectiveness against each risk assessment exercise.
Can someone please guide what is the right approach to move forward with a consistent and sustainable approach.
Thanks,