Principles Behind Cyber Risk Management

Carol J. Fox · 2017

In this chapter, principles from the ISO 31000:2009 international standard "Risk Management-Principles and Guidelines"1 are described to guide desirable and positive actions that are in line with the organization's enterprise-wide approach to governance and management of enterprise IT. Inclusive and transparent stakeholder involvement ensures that risk management remains relevant and can address new and ever-changing threats. Assessment methodologies, decisions, and resulting actions are customized based on the circumstances, proprietary knowledge, and the set of risks under consideration. Managing IT as an asset is an essential element of the creation and preservation of value. ISO 31000 also connects two COBIT 5 enablers: culture and people, skills and competencies. At the same time, it separates governance activities of evaluating, directing and monitoring (based on business needs) from the management activities of planning, building, running, and monitoring.

Read the paper · More papers on PaperTik