Skip to Main Content

Have you done your Data Risk Assessment?

Graphic with a red pause button, a yellow check mark, and a green play button and the words pause, verify, report at work underneath.

Departments are required to include cybersecurity risk assessments and mitigating controls as part of your department’s Internal Control Plan and system of internal controls.

If your department faces a system disruption or incident, or needs to respond to an IT Audit, you will need to be able to quickly identify what data you have and through what systems that data travels and resides.

To help you prepare for these types of events, CTR has created an informational document with four steps to perform a cybersecurity risk assessment that identifies and mitigates security risks.

Action steps:

See our CTR Cyber page for more cybersecurity internal controls and contact [email protected] with any incidents or suspected incidents of fraud or cyber threats or if you need support from our Statewide Risk Management Team.