An IT risk assessment helps you understand and document the security risks associated with a system, process or service. It considers the likelihood and potential impact of risks so you can determine appropriate safeguards and risk treatment.

The assessment provides a documented understanding of the system's security risks and the actions needed to address them. Identified risks may be accepted, mitigated, transferred, avoided or otherwise treated in accordance with the UM System Information Security Risk Management policy.

When Do I Need a Risk Assessment?

A risk assessment may be required when you are:

  • The technical or business owner of a designated UM Essential System
  • The technical or business owner of a designated Campus Covered Component (CCC)
  • Implementing a new system or technology
  • Making significant changes to an existing system or process
  • Storing, processing or transmitting sensitive or confidential information
  • Engaging a third-party vendor to provide technology, systems or services
  • As required by policy, audit or compliance obligations.

UM Essential Systems will be assessed on a three-year cycle.

Before You Begin

Gather information about the system or service, the data it handles, key contacts and owners, existing security controls and any third-party providers involved. Having this information available will help the assessment move more efficiently.

Our Risk Assessment Process

The risk assessment process consists of two phases. Both phases help identify, evaluate and address risks associated with a system or service.

  1. Assessment Phase: Validate our understanding of the system, information, threats, vulnerabilities and existing controls. Identify and evaluate risks and opportunities to strengthen the system's security posture.
  2. Mitigation Phase: Determine the appropriate risk treatment for identified risks, assign responsibility, establish target dates and implement the agreed-upon mitigation activities.

What to Expect

During the assessment, you may be asked to provide information about:

  • The system, application, process or service being assessed
  • The types of information involved
  • System owners and other responsible parties
  • How information is collected, stored, transmitted and accessed
  • Existing security controls and safeguards
  • Known vulnerabilities, risks or previous findings
  • Third-party providers or integrations
  • Planned changes or upcoming implementations

Need Help?

Not sure whether a risk assessment is required or where to begin? The Information Security team can help you determine the appropriate next steps.