Salesforce isn’t rocket science, but the software has an incredible array of tools, which is why securing it demands a unique (and sometimes complex) approach. Salesforce is responsible for the security of its platform, and the organization has done a tremendous job of repelling a constant barrage of external threats. It’s important to create a recurring process designed to assess your security posture and identify the changes necessary to effectively reduce risk. The following four steps will take your security to the next level: Define clear owner(s)
Source: https://www.helpnetsecurity.com/2021/05/07/security-risk-assessment-salesforce-use/