Holistic Approach to Information Security Risk Management

Pratik Sawant, KPMG, India · International Journal of Engineering Research and · 2020

Risk management is a very important area in information security.Risk management comprises of risk identification, risk assessment and risk treatment.Risk identification on current security infrastructure helps organizations to reveal vulnerabilities, threats and identify the risks that these two factors pose to their security infrastructure.Risk assessment helps in analyzing the identified risks using aspects like probability and impact and risk treatment helps in reducing the impact of the risks to an acceptable level [1].Risk management is mandatory requirement of ISO 27001:2013 and ISO 22301:2012 standards and the organization going for these certifications must comply with it.The eventual goal of a risk management activity is to define appropriate safeguards tailored to your company's risk profile and priorities.Risk management activity usually precedes and help define audit plans and facilitate the development of a corporate security plan.Qualified team members from information security department of an organization perform risk assessment at predefined period or after any change to provide reasonable assurance to the top management about the organization's risk profile.Risk management allows organizations to adopt security strategies that are tailored to their unique operating environment, threat landscape and business objectives.Riskbased security strategies deliver value to an organization by allowing it to understand the impact of risk and the efforts required to mitigate the risks.These security strategies help organizations in complying with regulations, thwart security attacks etc. Risk-based security strategies may differ markedly from the approaches currently adopted by many organizations.

Read the paper · More papers on PaperTik