RISK ASSESSMENT & ANALYSIS
Functionally, SAFETAG is a digital risk assessment framework. Risk assessment a systematic
approach to identifying and assessing risks associated with hazards and human activities.
SAFETAG focuses this approach on digital security risks. A SAFETAG audit will work to collect
the following types of information in order to assess the risks an organization faces.
Risk is the current assessment of the possibility of harmful events occurring. Risk is
assessed by comparing the threats an actor faces with their vulnerabilities, and their
capacity to respond to or mitigate emergent threats.
The SAFETAG evaluation revolves around collecting enough information to identify and
assess the various risks and an organization and its related actors face so that they can take
action strategically.
The Risk Equation
PROGRAM ANALYSIS
Program analysis identifies the priority objectives of the organization and determine its
capacities. This process exposes the activities, actors, and capacities of an organization.
Activities
Definition: The practices and interactions that the organization carries out in order to
accomplish their goals.
Example: This includes any activity that the organization carries out to accomplish its goals
and those that allow the organization to function (publishing, payment, fund-raising,
outreach, interviewing.)
What is the main purpose of the organization?
What are the processes the organization takes part in to carry out their work?
Actors
Definition: The staff, volunteers, partners, beneficiaries, donors, and adversaries associated
with the organization.
Example: The core organizational staff, the volunteers, maintenance, cleaning, security, or
other non-critical staff, the partner organizations, the individuals and groups that the
organization provides services to, groups of unorganized individuals who are opposed to
organizational aims, governmental and non-governmental high-power agents and
organizations that are opposed to the organizations aims.
Page 7 of 240