We use risk assessments to plan short- and long-term security projects, as well as to set priorities within our Security team.
The goal of risk assessments is to transfer, avoid, or mitigate risk. Our risk management process includes the following components:
Our primary tool, the SRR, assesses the risk exposure of every identified security threat across our environment and is the basis for most other risk management tools in play. We use the SRR to inform relevant groups (notably the Security team and the leadership/executive teams) regarding our knowledge of risk exposure.
We use procedural risk assessments—a standard process for analyzing the risk of various input—to make informed decisions around the associated risk exposure.
Each risk assessment leverages data tabulated in the SRR to articulate the impact of various risk scenarios and inform decision-making in relevant contexts.
We use development risk assessments for new major products or product features to ensure that we thoroughly evaluate critical security and legal controls.
- An initial assessment gauges the overall risk of the design.
- If our Security team identifies a high level of risk, we ask for more details in the product design document.
- Our Security team might ask for clarification around sensitive topics and require design changes or mitigation strategies to address new risk exposure.
- Follow-up risk assessments might be necessary depending on the complexity of the project.
FHIR® is a registered trademark of Health Level Seven International (HL7) and is used with the permission of HL7. Use of this trademark does not constitute an endorsement of products/services by HL7®.