Respected forum members,
A basic doubt. Can you please help me to understand if due diligence activity should give a risk rating basis the control sufficiency? That needs to be used to derive residual risk rating. Or there is somethin else process involved.
As per my understanding ,
Step 1- Conduct inherent risk assessment---> get a inherent score ( for ex, Rating x)
Step 2- conduct DD (basis criticality level and inherent risk score which is "x" here)---> get a score (for ex, rating "y")
Step 3- Asses residual risk (z) i.e z= x-y
Regards,
Aiswarya