Risk Management

Information Security Risk Management
Information Security Risk Management

Risk management is the process of identifying potential risks, analyzing them, and take precautionary steps to mitigate those risks. To understand risk management better, you must know about the following terms:

  1. Threat: that might cause harm like software compliance, human error, environmental factors, infrastructure issues, intellectual property, and human error etc.
  2. Vulnerability: a weakness that can be exploited
  3. Impact: degree of damage to an asset of an organization

So, risk is the possibility that a threat exploits a vulnerability leading to an adverse impact. These risks, or threats could arise from various sources including legal liabilities, human errors, strategic management errors, financial uncertainties, and natural disasters etc. Risk management strategies have become a top priority among IT companies to mitigate the risks related to Human Resource, Finance, Infrastructure, Network & IT security, intellectual property, and Customer’s Personal Identifiable Information (PII).

Risk management process contains steps which includes:

  1. Risk Identification­
  2. Risk Analysis
  3. Risk Assessment and Evaluation
  4. Risk Mitigation
  5. Risk Monitoring

ISO Guide 73:2009 is the vocabulary widely used for risk management, and provides definitions of generic terms related to risk management.

You may also like...

Leave a Reply