Advantages of Using a Dynamic Risk Management Approach
Valentin P. Măzăreanu · SSRN Electronic Journal · 2010
The increased spending for information technology leads to increased dependency on technology and thus to an increased vulnerability in front of risks that may arise in this area (system crashes, failures, information systems attacks etc.). So within the digital era risk management takes a new shape: information security risk management. The major objective of information security risk management is to protect such IT assets as data, hardware and software, personnel and facilities from all threats that may arise outside or inside the organization. The aim is to avoid or minimize losses by selecting and implementing appropriate security measures. Information security risk management is a concept of increasingly widespread, covering a wide range of issues. According to Wespi these issues can be grouped into static security risk management and dynamic security risk management. In the case of dynamic risk management the response to identified risks should occur immediately. So it is imperative to adapt classical models of risk management. In this paper we address some of the most recent factors that generate information security risks and the manner in which a dynamic approach to risk management leads to a new model that can bring the difference between success and failure.