Skip to main content
Guidance

Risk management

How to understand and manage the cyber security risks for your organisation.

Page 11 of 15

Component driven risk management methods

An introduction to using component driven risk management in cyber security.







Note

We have deliberately not referenced the CESG Risk Management method using a component driven approach (known as IS1/2). This standard has been formally deprecated by CESG and the NCSC no longer think it's appropriate to use as part of a risk management approach. Organisations should transition from static accreditation and risk management decision making processes, to approaches that support ‘secure by design’ and continuous assurance (such as those listed in the table above, or the basic method provided in this guidance).

Published

Publish date

Reviewed

Version

2.0