Risk assessment and management of information assets
Stephen Hancock · Engineering & Technology Reference · 2012
Assessing and managing the risks associated with IT and information assets is one of the most challenging tasks facing a Chief Information Officer or Chief Information Security Officer. Yet, with so many day-to-day pressures on time and resources, it is perhaps not surprising that it often does not get their full attention. However, with frequent reports of new vulnerabilities, hacking attacks and data breaches, it is an essential activity. This article explains what information security risk assessment and management is, and why it is necessary. It identifies some popular frameworks for carrying out an assessment and discusses their common features including identifying assets, threats and vulnerabilities, impact and likelihood. It summarises the process of undertaking a risk assessment and how the identified risks are subsequently managed and monitored. It also identifies some of the pitfalls and challenges that organisations may face and looks at ways of making the process meaningful to the business.