Risk Management

Risk management is the systematic process of understanding what could harm an organization's information and systems and deciding what to do about it. It begins with identifying risks, the combination of threats, vulnerabilities, and the value of what is at stake, and analyzing their likelihood and potential impact so they can be compared and prioritized.

Within strategic governance, risk management is the discipline that directs the whole program. It tells leadership where exposure is greatest and ensures that policies, controls, and investments are driven by actual risk rather than habit or the latest headline. It also connects security to the organization's stated risk appetite, the level of risk it is willing to accept in pursuit of its goals.

Once risks are understood, they are treated. The common options are to mitigate, by applying controls that reduce likelihood or impact, transfer, by shifting risk to another party through insurance or contracts, accept, by acknowledging and tolerating a risk within appetite, or avoid, by not undertaking the activity. Treatment decisions are recorded, usually in a risk register, with owners assigned.

Risk management matters because resources are finite and threats are not. Monitoring keeps the picture current, because risks change as systems, threats, and the business evolve, and a decision that was sound last year may need revisiting.

References#

  • ISO 31000, Risk management guidelines.
  • NIST SP 800-39, Managing Information Security Risk.

Cookie Consent

We use cookies to enhance your experience. Learn more