Enterprise Risk Management
Enterprise risk management (ERM) is a set of practices, methods, and processes adopted by organizations to manage and monitor risks. ERM is a structured process for managing various risks that can adversely impact business objectives. For effective risk management, it is important for the organization to determine its appetite for risk.
Risk Management Process Steps
Risk management is a process in which potential risks are identified, monitored, and managed. The following subsections describe the five steps to effective risk management.
Asset Identification
The first step is the identification of assets that are critical to the organization and that need to be adequately protected. Assets can be in the form of data, hardware, software, and people. Once assets are identified, they should be classified in terms of criticality and sensitivity.
The purpose of classification is to prioritize the assets that need to be protected. Classification also...