Steps for managing risk
Good article on risk management on Computerworld by Samir Kapuria.
In this article, Samir described a 3 step process in which a security assurance team should take for risk management. The only thing I would recommend changing is to separate the incident response step from the Application step. Right now Samir has both mixed into one.
The risk management process is continuous; it should never be considered a point-in-time solution.
