Answer:
In our book, IT Auditing for Financial Institutions, we discuss the IT risk assessment and offer a very practical model for conducting the risk assessment. The model follows three simple steps to 1. Identify, 2. Measure, and 3. Prioritize risk.
First published on BankersOnline.com 7/15/02