There is a paragraph in the Secure development policy which states:
In addition to the risk assessment performed according to the Risk Assessment and Risk Treatment Methodology, Head of RD must perform the annual assessment of the following:
the risks related to unauthorized access to the development environment
the risks related to unauthorized changes to the development environment
technical vulnerabilities of the IT systems used in the organization
the risks a new technology might bring if used in the organization
the risk a new development methodology and/or programming language might bring if used in the organization
the risks related to licensing requirements
The question is, is this assessment to be done in the Risk Register or is it an additional document that needs to be drafted by the Head of R&D?
Thanks
This website stores cookies on your computer. These cookies are used to collect information about how you interact with our website and allow us to remember you. We use this information in order to improve and customize your browsing experience and for analytics and metrics about our visitors both on this website and other media. To find out more about the cookies we use, see our Privacy Policy.
If you decline, your information won't be tracked when you visit this website. A single cookie will be used in your browser to remember your preference not to be tracked.