Procedure Step:Risk Assessment
Audit Step:
Determine whether the agency Department has conducted a comprehensive risk assessment for the application that examines the protection mechanisms and most likely vulnerabilities including identifying:
- All possible system vulnerabilities;
- The probability that these vulnerabilities will be exploited;
- The possible impact from such exploitation; and
- The appropriate steps to mitigate risks.
Purpose:
To obtain an understanding of how access to the system is determined and at what levels access can be restricted.

