Risk response and monitoring
In the last few chapters, we looked at the best practices for performing risk identification and the best practices for risk assessment. In this and the upcoming chapters, we will learn about the various practices of risk response. The following diagram illustrates the IT risk management life cycle.
Figure 10.1 – IT risk management life cycle
There can be multiple responses to a risk; however, the job of the risk manager is to assess each of the responses with respect to the budget, time, external regulatory factors, and any disruptions to the current services and identify the response that would most optimize the risk for available resources at the time. The risk manager should then propose these responses to management and relevant stakeholders to obtain buy-in and implement the agreed controls in a reasonable timeframe.
It is important for an organization to monitor the implemented solution over time to confirm...