Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| pub:trust_center:risk_framework [21.07.2026 13:38] – Update Risk Framework with comprehensive cross-links for navigation Predrag Tasevski | pub:trust_center:risk_framework [21.07.2026 13:57] (current) – [Risk Governance] Predrag Tasevski | ||
|---|---|---|---|
| Line 50: | Line 50: | ||
| For each risk, we choose a strategy: | For each risk, we choose a strategy: | ||
| - | | Strategy | + | ^ Strategy |
| - | |---|---| | + | |
| | **Mitigate** | Deploy a Web Application Firewall (WAF) to reduce likelihood of exploitation | | | **Mitigate** | Deploy a Web Application Firewall (WAF) to reduce likelihood of exploitation | | ||
| | **Accept** | Accept risk of rare data center outage (handled by AWS redundancy) | | | **Accept** | Accept risk of rare data center outage (handled by AWS redundancy) | | ||
| Line 69: | Line 68: | ||
| ====== Risk Categories We Manage ====== | ====== Risk Categories We Manage ====== | ||
| - | | Risk Category | + | ^ Risk Category |
| - | |---|---|---|---| | + | |
| | **Security Risks** | Data breach, malware, unauthorized access, unpatched vulnerability | Encryption, access control, patch management, monitoring | [[pub: | | **Security Risks** | Data breach, malware, unauthorized access, unpatched vulnerability | Encryption, access control, patch management, monitoring | [[pub: | ||
| | **Availability Risks** | Platform outage, slow performance, | | **Availability Risks** | Platform outage, slow performance, | ||
| Line 79: | Line 77: | ||
| ====== Risk Governance ====== | ====== Risk Governance ====== | ||
| - | | Role | Responsibility | + | ^ Role ^ Responsibility |
| - | |---|---|---| | + | |
| | **CEO (Predrag)** | Approve risk appetite; allocate budget for risk mitigation; review critical risks quarterly | [[pub: | | **CEO (Predrag)** | Approve risk appetite; allocate budget for risk mitigation; review critical risks quarterly | [[pub: | ||
| | **CTO (Peter)** | Identify technical risks; implement controls; track patch deployment and incident response | [[pub: | | **CTO (Peter)** | Identify technical risks; implement controls; track patch deployment and incident response | [[pub: | ||