Risk management is an organizational-wide activity
Information security professionals must develop a comprehensive risk management strategy that enables an organization to establish consistent mechanisms for continuous assessment, response, and monitoring of information security risks. This approach allows the information security professional to engage the organization transparently and systematically, fostering greater acceptance within the organization. To gain a deeper understanding of your organization, consider the following examples and insights from various parts of the business:
Figure 4.1 – Relationships between information systems and the organization
Let’s take a closer look:
- Business operations: Key areas to explore include finance, HR, and manufacturing. Examining business operations is crucial for understanding the following:
- The acceptable risk levels for each business unit concerning information systems. For example...