This process guide is intended for use by Cybersecurity Services Division, business areas and other security praconers to help understand Department IT security risks, prepare and conduct Security Threats and Risks Assessments (STRAs) if need be, in a mely manner as new projects are initiated. This process guide is intended to provide a context for assessing and managing IT risks and reporng high exposure risks to management and risk owners.