Ask Question, Ask an Expert

+61-413 786 465

info@mywordsolution.com

Ask Homework Help/Study Tips Expert

Risk Management

Security is everyone's responsibility. Security awareness poster. U.S. Department of Commerce/Office of Security.

A complete treatment of the topic of risk management is further than the scope of this editorial. We will however, provide a helpful definition of risk management, draw round a usually used process for risk management, and describe some basic terminology.

The CISA Review Manual 2006 provides the following definition of risk management: "Risk management is the process of identifying vulnerabilities and threats to the information resources used by an organization in achieving business objectives, and make a decision what

Countermeasures, if any, to obtain in reducing risk to a suitable level, based on the value of the information reserve to the organization."

There are two things in this description that may require some explanation. First, the procedure of risk management is an ongoing iterative process. It must be frequent without letting up. The business environment is continuously changing and new fear and vulnerabilities come out every day. Second, the choice of countermeasures (controls) used to manage risks have to strike a balance between efficiency, cost, usefulness of the countermeasure, and the worth of the informational asset being sheltered.

Risk is the probability that something bad will occur that causes damage to an informational asset (or the loss of the asset). Vulnerability is a fault that could be used to put in danger or cause harm to an informational asset. A risk is anything (man made or act of nature) that has the possible to reason harm.

The probability that a danger will use a vulnerability to reason harm creates a risk. When a warning does use a vulnerability to impose harm, it has a crash. In the context of information security, the crash is a loss of integrity, confidentiality, availability, and possibly other losses (loss of life, lost income, and loss of real possessions). It should be pointed out that it is not possible to identify all risks, nor is it probable to remove all risk. The enduring risk is called residual risk.

A risk assessment is carried out by a team of people who have knowledge of exact areas of the trade. association of the team may contrast over time as dissimilar parts of the business are assessed. The measurement may use a prejudiced qualitative analysis based on informed opinion, or where reliable dollar statistics and historical information is existing, the analysis may use quantitative analysis.

The ISO/IEC 27002:2005 Code of put into practice for information security management suggests the subsequent be examined during a risk assessment

  • interactions and operations management,
  • access control,
  • security policy,
  • organization of information security,
  • asset management, human resources security,
  • physical and environmental security,
  • information security event management,
  • business continuity management, and
  • regulatory compliance.
  • information systems acquisition,
  • development and maintenance,

In wide provisions the risk management process consists of

1.   Recognition of assets and approximation their value. Include: building, persons, software, hardware, data (print, electronic, other), and supplies.

2.   carry out a threat assessment. Include: Acts of natural world, accidents, acts of war, malicious acts originating from inside or outside the association.

3.   Conduct a susceptibility assessment, and for each vulnerability, calculate the probability that it will be exploited. Evaluate policies, events, standards, training, physical security, quality control, technological safety

4.   compute the collision that each threat would have on each asset. Use qualitative analysis or quantitative analysis.

5.   recognize, select and implement suitable controls. offer a comparative response. Consider efficiency, cost efficiency, and value of the asset.

Evaluate the efficiency of the control procedures. make sure the controls provide

For any known risk, Executive Management can decide to accept the risk based upon the qualified low value of the asset, the comparative low rate of incidence, and the comparative low impact on the business. Or, management may prefer to mitigate the risk by selecting and implementing appropriate control actions to reduce the risk. In a number of cases, the danger can be transferred to an additional business by buying assurance or out-sourcing to another business. The reality of some risks may be doubtful. In such cases leadership may choose to deny the risk. This is itself a possible risk.

Homework Help/Study Tips, Others

  • Category:- Homework Help/Study Tips
  • Reference No.:- M9511254

Have any Question?


Related Questions in Homework Help/Study Tips

Question instructions use mla formatfor each word1find the

Question: Instructions: Use MLA Format For each word 1. Find the Part of Speech 2. Find the Definition (write general definition) 3. Create an Original Sentence to demonstrate that you understand the word. For example: b ...

Case study plain view open fields abandonment and border

Case Study : Plain View, Open Fields, Abandonment, and Border Searches as They Relate to Search and Seizures Officer Jones asked the neighborhood's regular trash collector to put the content of the defendant's garbage th ...

Question in this weeks reading we looked at accounts

Question: In this week's reading we looked at accounts, identity, authentication, and account recovery. There is an old adage that says, "You can never be too safe. When it comes to the digital world, it's very true. Cyb ...

Question research the functions importance and role of fat-

Question: Research the functions, importance, and role of fat- and water-soluble vitamins. Create a 12- to 15-slide Microsoft® PowerPoint® presentation that includes the following: • A title slide • An introductory slide ...

Tub for twomary the front desk agent who had been with the

TUB FOR TWO Mary, the front desk agent who had been with the Boden Oceanside Resort and Lodge for nearly six months now, was trying her best to persuade the Wade party to take a look at one of the stylish executive suite ...

Question mr c a 32-year-old single man is seeking

Question: Mr. C., a 32-year-old single man, is seeking information at the outpatient center regarding possible bariatric surgery for his obesity. He reports that he has always been heavy, even as a small child, but he ha ...

Question this assignment can be a 3-5 minute video or a 2-4

Question: This assignment can be a 3-5 minute video OR a 2-4 page written paper (your choice). See instructions below for further details. According to the textbook, the current world economy is increasingly becoming int ...

Interview interview a member of a military family or a

Interview: Interview a member of a military family or a helping professional working with military families. Provide details of that person's experiences and what you consider critical elements that provide insight into ...

Assignment - art of historychoose 3 pictures of the book

Assignment - Art of history Choose 3 pictures of the book (attached) and write 4-5 pages about the pictures, like why chose them and what elements are used in these arts and how does it inspires me and write some more st ...

Explain and provide an example ofnbsphabituation learning

Explain and provide an example of habituation learning. Why is this type of learning useful?

  • 4,153,160 Questions Asked
  • 13,132 Experts
  • 2,558,936 Questions Answered

Ask Experts for help!!

Looking for Assignment Help?

Start excelling in your Courses, Get help with Assignment

Write us your full requirement for evaluation and you will receive response within 20 minutes turnaround time.

Ask Now Help with Problems, Get a Best Answer

Why might a bank avoid the use of interest rate swaps even

Why might a bank avoid the use of interest rate swaps, even when the institution is exposed to significant interest rate

Describe the difference between zero coupon bonds and

Describe the difference between zero coupon bonds and coupon bonds. Under what conditions will a coupon bond sell at a p

Compute the present value of an annuity of 880 per year

Compute the present value of an annuity of $ 880 per year for 16 years, given a discount rate of 6 percent per annum. As

Compute the present value of an 1150 payment made in ten

Compute the present value of an $1,150 payment made in ten years when the discount rate is 12 percent. (Do not round int

Compute the present value of an annuity of 699 per year

Compute the present value of an annuity of $ 699 per year for 19 years, given a discount rate of 6 percent per annum. As