Differences
This shows you the differences between two versions of the page.
| Next revision | Previous revision | ||
| pub:trust_center:risk_framework [21.07.2026 13:28] – Risk Assessment Framework - Overview of how we manage risks Predrag Tasevski | pub:trust_center:risk_framework [21.07.2026 13:57] (current) – [Risk Governance] Predrag Tasevski | ||
|---|---|---|---|
| Line 15: | Line 15: | ||
| * **Business continuity** — Infrastructure failures, natural disasters, vendor issues | * **Business continuity** — Infrastructure failures, natural disasters, vendor issues | ||
| - | By systematically assessing and managing these risks, we reduce the likelihood of problems and our ability to recover quickly if they occur. | + | By systematically assessing and managing these risks, we reduce the likelihood of problems and improve |
| ====== Our Risk Management Approach ====== | ====== Our Risk Management Approach ====== | ||
| - | We use **ISO 31000** (international risk management standard) to: | + | We use **ISO 31000** (international risk management standard) combined with **ISO 27005** (information security risk) to: |
| === 1. Identify Risks === | === 1. Identify Risks === | ||
| Line 50: | Line 50: | ||
| For each risk, we choose a strategy: | For each risk, we choose a strategy: | ||
| - | | Strategy | + | ^ Strategy |
| - | |---|---| | + | |
| | **Mitigate** | Deploy a Web Application Firewall (WAF) to reduce likelihood of exploitation | | | **Mitigate** | Deploy a Web Application Firewall (WAF) to reduce likelihood of exploitation | | ||
| | **Accept** | Accept risk of rare data center outage (handled by AWS redundancy) | | | **Accept** | Accept risk of rare data center outage (handled by AWS redundancy) | | ||
| Line 65: | Line 64: | ||
| * **Access control violations** — Any unauthorized access attempts | * **Access control violations** — Any unauthorized access attempts | ||
| - | Results are reviewed in [[pub: | + | Results are reviewed in [[pub: |
| ====== Risk Categories We Manage ====== | ====== Risk Categories We Manage ====== | ||
| - | | Risk Category | + | ^ Risk Category |
| - | |---|---|---| | + | | **Security Risks** | Data breach, malware, unauthorized access, unpatched vulnerability | Encryption, access control, patch management, monitoring |
| - | | **Security Risks** | Data breach, malware, unauthorized access, unpatched vulnerability | Encryption, access control, patch management, monitoring | | + | | **Availability Risks** | Platform outage, slow performance, |
| - | | **Availability Risks** | Platform outage, slow performance, | + | | **Compliance Risks** | Failed audit, regulatory violation, GDPR incident notification | Security controls, incident response, compliance procedures |
| - | | **Compliance Risks** | Failed audit, regulatory violation, GDPR incident notification | Security controls, incident response, compliance procedures | | + | | **Operational Risks** | Human error, misconfiguration, |
| - | | **Operational Risks** | Human error, misconfiguration, | + | | **Vendor Risks** | Vendor breach, loss of service, vendor data mishandling | Vendor assessment, contracts, monitoring |
| - | | **Vendor Risks** | Vendor breach, loss of service, vendor data mishandling | Vendor assessment, contracts, monitoring | | + | |
| ====== Risk Governance ====== | ====== Risk Governance ====== | ||
| - | | Role | Responsibility | + | ^ Role ^ Responsibility |
| - | |---|---| | + | | **CEO (Predrag)** | Approve risk appetite; allocate budget for risk mitigation; review critical risks quarterly |
| - | | **CEO (Predrag)** | Approve risk appetite; allocate budget for risk mitigation; review critical risks quarterly | | + | | **CTO (Peter)** | Identify technical risks; implement controls; track patch deployment and incident response |
| - | | **CTO (Peter)** | Identify technical risks; implement controls; track patch deployment and incident response | | + | | **Operations (Alexander)** | Identify operational risks; manage access control; support incident response |
| - | | **Operations (Alexander)** | Identify operational risks; manage access control; support incident response | | + | | **All Employees** | Report risks or suspicious activity when discovered |
| - | | **All Employees** | Report risks or suspicious activity when discovered | | + | |
| ====== Our Risk Appetite ====== | ====== Our Risk Appetite ====== | ||
| Line 109: | Line 106: | ||
| ✅ **Compliance is maintained** — We meet GDPR, NIS2, CRA, DORA requirements | ✅ **Compliance is maintained** — We meet GDPR, NIS2, CRA, DORA requirements | ||
| ✅ **Continuous improvement** — We get better based on results and lessons learned | ✅ **Continuous improvement** — We get better based on results and lessons learned | ||
| - | ✅ **Transparency** — We report incident response time and uptime to you regularly | + | ✅ **Transparency** — We report incident response time and uptime to you regularly |
| + | |||
| + | ====== Regulatory Alignment ====== | ||
| + | |||
| + | Our risk management framework supports compliance with: | ||
| + | |||
| + | * [[pub: | ||
| + | * [[pub: | ||
| + | * [[pub: | ||
| + | * [[pub: | ||
| + | * [[pub: | ||
| ====== See Also ====== | ====== See Also ====== | ||
| - | * [[pub: | + | * [[pub: |
| - | * [[pub: | + | * [[pub: |
| + | * [[pub: | ||
| + | * [[pub: | ||
| * [[pub: | * [[pub: | ||
| - | * [[pub:trust_center:isms_policy|Information Security Policy]] | + | * [[pub:company:accountability_chart|Accountability Chart]] — Risk management roles |
| ====== Questions? ====== | ====== Questions? ====== | ||
| Line 123: | Line 132: | ||
| → Email us: **security@unicis.tech** | → Email us: **security@unicis.tech** | ||
| + | |||
| + | ---- | ||
| + | |||
| + | ==== Navigation ==== | ||
| + | |||
| + | ← [[pub: | ||
| ---- | ---- | ||