Cybersecurity Risk Planning and Management

Cynthia Brumfield, Brian Haugli · 2021

This chapter discusses how to establish knowledge of the systems in place and how to inform management of those systems' risk profiles. It also discusses how to develop plans for dealing with the highest priority risks. The chapter helps the reader develop an understanding necessary to manage cybersecurity risk to systems, assets, data, and capabilities. Cybersecurity risk management is simply looking at what could go wrong and then coming up with ways to minimize those problems. The chapter includes some references to help IT professionals learn more about applicable technical standards that could help they develop their organizations' governance policy. All organizations need to pay attention to traditional and emerging information technology (IT) hardware assets and an extensive list of internet of thing devices and specialized equipment IT professionals' organization uses. A risk assessment is simply an effort to identify threats to IT professionals' organization, how likely they are, and the consequences of the dangers.

Read the paper · More papers on PaperTik