Critical concepts for risk assessment and management
This section is the essence of the critical concepts that will be widely used across this book, your day-to-day job, and any ISACA exam including the CRISC.
The risk profile
The purpose of the risk management function is to optimize the risk decisions for an enterprise. The risk profile is the overall risk exposure of the organization to any type of risk. There are many factors that could impact the risk profile of an organization, such as new regulations, changes in the underlying technology, changes in the business objectives, mergers and acquisitions, direct or indirect competitors, and more. This is all part of the enterprise risk profile and will impact all businesses and functions of the organization.
The IT risk profile of an organization is the overall identified IT risk to which the enterprise is exposed. Similar to the enterprise risk profile, the IT risk profile can be dependent on many external factors such as...