3. Identifying and Selecting Measures

Once threats are identified, the following steps must be taken:

  • Identification: Pinpoint threats based on the specific vulnerabilities of the system.

  • Categorization: Group threats according to their "Risk Impact" (e.g., High, Medium, Low).

  • Selection of Measures: Choose appropriate security controls (Preventive, Detective, or Responsive) to mitigate the identified threats.