I started by sitting down with the owner and laying out the following high-level
procedure, adapted from those of the National Institute of Standards and Technology
and SANS3
:
1. Determine what must be protected (assets)
2. Identify and define possible threats to those assets
3. Determine and prioritize the risks.
4. Assess responses to the risks.
She agreed with this procedure, and we started with determining assets.