Information Security Management: Module 3
Risk Management
Learn what risk is, how to express risk to others and how to make risk statements.
Estimated reading time
5 minutes
What is risk?
Risk in information security refers to the possibility of a threat will take advantage of a vulnerability of certain information and compromise an organisation.
According to Rhodes, risk is best managed when involving all parties who should be concerned about it. It must also support the organisation's goals. It is also crucial for all parties involved to have a clear risk appetite, risk acceptance criteria and risk owners who can take accountability.
Creating risk statements
According to Rhodes, the risk statement briefly explains the risk to stakeholders. It must convey the incident that is likely to happen, the consequence that will happen when security is compromised and the impact it will have to the stakeholders or business.
One simple format could look like this:
There is a risk that [event/incident] occurs leading to [consequence] that causes [impact].
If-then statements can also be used to express the risk to stakeholders, risk owners and other affected parties.
Here are some examples:
- If the server is infected, then an outage is likely to occur. Any outage will result in $500 of lost sales for every 15 minutes of downtime.
- There is a risk that a staff member will click on a malicious link in an email message leading to the installation of malicious software that causes the computer system to be unavailable to users.
Communicating risks
The stakeholders may not always be someone in IT or an information security professional, so the risk must be communicated through language the stakeholders understand. Different people also value different aspects of the business or the information.
- Technology managers may care about things like system availability measured in percentages.
- Business managers may care about the number of transactions completed successfully per hour.
- Executive managers care about market share which they could measure in their own metrics.