Understanding the ownership and management of information security risk
Information security risk is critical for organizations, especially in light of the growing number of large-scale government and private sector information systems breaches. In the past, many organizations viewed information security risk as solely owned by the IT division. However, this is not an acceptable practice, and it is crucial to understand the concept of risk ownership versus risk management.
The ability to own risk is tied to authority and the ability to commit funds to reduce risk. Senior leaders can fund risk reduction efforts, as well as change the direction of organizational actions and culture. It is critically important that risks to the organization be effectively communicated to senior leadership with well-thought-out plans to reduce risk.
While risk ownership sits with an organization’s executive team, it is the responsibility of the information security professional to deliver...