# Secureframe

canonical: https://secureframe.com/risk-management-kit

- ### Risk appetite worksheet — Follow these steps to establish a risk appetite framework that effectively guides better decision-making, supports strategic objectives, and enhances your organization’s operational resilience.

What’s included:  

- Step-by-step guidance on defining an appropriate risk appetite for your business
- Practical tips for implementing risk appetite successfully into your organization’s processes
- ### Risk appetite statement template — A risk appetite statement specifies the types of risks facing your organization, describes the acceptable levels of risk for different activities or decisions, and outlines who within the organization is responsible for making decisions about risk. 

What’s included:

- A complete, customizable risk appetite statement template that's easy to tailor to your organization
- Track version history and changes made to keep your risk appetite statement up-to-date
- ### Third-party risk management policy template — Use this template to help build a solid foundation for managing your third-party relationships, whether you’re creating a third-party risk management policy for the first time or looking to strengthen your current policy.

What’s included:

- Establish strong controls and processes for managing third-party security risks
- A complete, auditor-approved template that's easy to tailor to your organization
- ### Incident response plan template — An incident response plan defines a predetermined set of instructions or procedures to detect, respond to, and limit the consequences of a security incident.

What’s included:

- A defined, systematic incident response process for information security incidents
- Testing methods to ensure the plan is effective and practical
- ### Disaster recovery plan template — Define a contingency plan that outlines how your organization will recover and restore its critical systems, operations, and data in the event of a disaster. Use this template to kick off your disaster recovery planning and customize it based on your organization's specific risks and objectives.

What’s included:

- Outline disaster recovery strategies and procedures
- Establish expectations, priorities, and recovery stages if a disaster occurs
