USPS Homepage Skip Navigation Home   |   Help   |   Sign In
  Find a ZIP Code   /   Calculate Postage   /   Print a Shipping Label   /   Schedule a Pickup   /   Locate a Post Office   /   Track & Confirm  
Main Navigation Bar Business Household Buy Stamps and Shop All Products and Services About USPS and News
 
Go to previous section of document Link to chapter contents   Go to next section of document

4-5 Independent Risk Management

4-5.1 Independent Risk Assessment

Independent risk assessments are conducted by organizations that are separate and distinct from those responsible for the development and operation of the information resources. Such assessments will follow the independent risk assessment guidelines provided in Handbook AS-805-A, Information Security Assurance.

Note: Independent processes (e.g., independent risk assessment, independent code review, independent security test validation, independent penetration testing and vulnerability scans) are evaluations conducted by independent personnel, contractors, or vendors for the purpose of applying rigorous evaluation standards to information resources. An independent process is conducted by an organization that is separate and distinct from those responsible for the development and operation of the information resource.

4-5.2 Criteria for Conducting Independent Risk Assessments

An independent risk assessment may be recommended during the business impact assessment (BIA) process when information resources are:

a. Publicly accessible.

b. Developed, hosted, or managed primarily by non-Postal Service personnel.

c. Highly visible or have high impact.

Note: An independent risk assessment may be required at any time by the CIO/VP IT; manager, CISO; or vice president of the functional business area.

Go to previous section of document Link to chapter contents   Go to next section of document
 
       Site Map    Contact Us    Affiliates    Gov't Services    Jobs     |    National & Premier Accounts
Copyright © 1999-2006 USPS. All Rights Reserved.Terms of Use  Privacy Policy  No FEAR Act EEO Data
Postal Inspectors Web Page  Postal Inspectors
Preserving the Trust
Inspector General Web Page Inspector General
Promoting Integrity