Week 2 Assignment - Risk Management
PSmarkup_RISKMANAGEMENT.docx.pdf
26.3% Results of plagiarism analysis from 2022-04-16 11:48 UTC
RISKM ANAGEM ENT.docx
Date: 2022-04-16 11:47 UTC
All sources 25 Internet sources 9 Plagiarism Prevention Pool 16
[0] from a PlagScan document dated 2019-01-29 17:50
16.4% 26 matches
[1] answeregy.com/what/what-is-security-policy-in-information-security.php
5.1% 10 matches
[2] en.wikipedia.org/wiki/Information_security
7.6% 17 matches
[3] from a PlagScan document dated 2021-02-17 20:17
5.3% 14 matches
[4] from a PlagScan document dated 2021-12-14 06:51
4.9% 13 matches
[5] from a PlagScan document dated 2021-11-27 13:32
3.7% 12 matches
[6] from a PlagScan document dated 2021-09-10 11:47
3.1% 11 matches
[7] from a PlagScan document dated 2019-01-27 14:14
3.6% 6 matches 1 documents with identical matches
[9] from a PlagScan document dated 2018-06-14 06:09
2.3% 8 matches
[10] from a PlagScan document dated 2018-05-30 04:42
2.6% 9 matches
[11] from a PlagScan document dated 2022-04-04 07:10
2.5% 5 matches
[12] www.information-security-today.com/can-you-do-cyber-security-without-a-degree/
2.1% 5 matches
[13] www.sciencedirect.com/topics/computer-science/information-risk-management
2.8% 5 matches
[14] from a PlagScan document dated 2019-07-19 08:38
1.6% 2 matches
[15] from a PlagScan document dated 2019-01-27 22:18
1.8% 3 matches
[16] www.geeksforgeeks.org/what-is-information-security/
0.9% 4 matches
[17] from a PlagScan document dated 2020-08-04 13:49
1.1% 3 matches
[18] www.thealternativeboard.com/strategic-business-plan
1.1% 3 matches
[19] from a PlagScan document dated 2018-05-11 08:05
0.9% 1 matches
[20] www.researchgate.net/publication/315535909_Stimulating_employee_ambidexterity_and_employee_engagement_in_SMEs
0.6% 1 matches
[21] corporatefinanceinstitute.com/resources/knowledge/strategy/strategic-planning/
0.7% 1 matches
[22] from a PlagScan document dated 2020-12-16 14:39
0.7% 2 matches
[23] from a PlagScan document dated 2021-01-26 15:25
0.5% 1 matches
[24] from a PlagScan document dated 2020-05-13 18:28
0.3% 1 matches
[25] www.linkedin.com/company/wydawnictwo-uniwersytetu-lodzkiego
0.5% 1 matches
6 page s, 931 words
PlagLe v e l: 26.3% se le cte d / 31.6% ov e rall
42 matches from 26 sources, of which 9 are online sources.
Se ttings
Data policy: Compare with web sources, Check against my documents, Check against the Plagiarism Prevention Pool
Sensitivity: High
Bibliography: Consider text
Citation detection: Reduce PlagLevel
Whitelist: --
1 [2]
Information Security Risk Management
Name
Course
Institution
Date
2
Risk management and information security
Risk management involves identifying, analyzing, and responding to threats and
uncertainties while controlling the impact of risks on business goals. Information security [0]
on the other hand is the protection of information from unauthorized access and other
activities that may lead to destruction and disruption of an organization's information and
data. However, information security is not all about preventing unauthorized access. It [2] [2]
also involves “preventing unauthorized use, disclosure, disruption, modification, [1]
inspection, recording or destruction of information” (Garg, 2021). Risk management is [0]
one of the ways through which data security is achieved. [2]
Information security is different from information risk management in that
information security involves protecting information while information risk management
involves the identification, evaluation and treatment of information risks within the
organization. It involves addressing all the uncertainties surrounding the use of [4]
information in an organization. To manage information risks, a company puts in place [0]
policies and procedures that govern data use and reduce information vulnerabilities,
cyber-attacks, and poor security from third party vendors. While information security [2]
may include things like protective passwords, information risk management involves
assessment of information risks, having a clear risk management program, and
implementation of necessary policies. Information risk management promotes
information security. [1]
3
Security Policies and How They Factor Into Risk Management
In any organization, compliance is essential and it requires clear policies and
procedures. Policies provide direction and guidance on the appropriate actions that can [0]
lead to consistency, effectiveness, and clarity on the organization's operations. Policies [7]
comprise of internal standards that employees have to meet to avoid legal and compliance
risks. An information security policy is essential for an organization to protect sensitive [1]
information. The Security Scorecard (2021) describes information security policy as a set [1]
of “rules and processes for workforce members, creating a standard around the acceptable [1]
use of the organization's information technology, including networks and applications to
protect data confidentiality, integrity, and availability The policies on information ”.
security aim at achieving important information principles such as confidentiality,
integrity, and availability. The policies ensure proper management of information, best
practices, corporate security protocols, and adherence to security measures. All these [12]
enhance information security risk management. The organization prevents information
risks because through the policies, there is compliance, appropriate access to IT, and
detection of information threats. Generally, an information security policy ensures a high [13]
level of control and protection of an organizations information which increases
information security. [13]
Responsibilities for Both IT and Non-IT Leaders in Information Risk Management
Both IT and non-IT leaders must participate in information risk management to
achieve effectiveness. Senior leaders in an organization whether they're IT experts or not [13]
are accountable to the success of risk management programs. Their responsibilities [22]
include; [13]
4
Risk Assessment
All leaders have to participate in risk assessment and ensure the criteria used in
assessments are effective across all the functions of the organization. The senior [17]
leadership must agree on the used criteria and ensure the whole organization has a
common understanding on the risk. It is their role to understand the risk, its severity, and [11]
the effects on the organization's operations so that they can ensure there are necessary
strategies to mitigate the risks. [22]
Risk control
Leaders have the power to control risks by allocating the necessary resources to
reduce or eliminate the risks. Both IT and non-IT leaders have to assume accountability
for risk control. “Risk control at the senior leadership level should be conducted within [9]
the context of strategic business planning Ritcher, & Haddad, 2015). The leaders must ” ( [0]
also ensures employees in the organization have the capability to control the risks. This [0]
can be done by ensuring employees are educated and trained on how to implement
appropriate strategies of controlling the information risks. [0]
Creating Organizational Awareness about Risks
IT and non-IT leaders must ensure employees understand that information risks
exist and what their consequences are. According to Jedynak and Bak (2020), they must [0]
5
also lead in implementing the necessary policies to information security. is will Th [0]
encourage everyone in the organization to participate in information risk management. [0]
How a Risk Management Plan Can Be Tailored to Produce Information and
System-Specific Plans
A risk management plan refers to a written document detailing the process of risk
management in an organization. The plan contains all the information about the potential [0]
risks to the organization which the stakeholders have identified and evaluated. A risk [0]
management plan can produce specific information through the team brainstorming and
identifying the risks that are affecting the organization. While working through the risk [0]
management plan process, the team can also identify emerging risks and the risk that can
arise in the future. Therefore, system-specific plans can be tailored cover and mitigate to [0]
both current, emerging, and future risks. Therefore, the plan will comprise of details of [6]
managing different risks, their costs, and the expected results. Through the plan, the [0]
organization will also understand the risks that are worth eliminating, the ones that are
essential to the achievement of organizational goals, and the ones that will have a positive
impact on the company's bottom line.
6
References
Garg, R. (2021). What is Information Security? Retrieved from [1] [0]
https://www.geeksforgeeks.org/what- -information-security/is
Jedynak, P., & Bąk, S. (2020). The role of managers in risk management. In
Michałkiewicz A., Mierzejewska W.(red.), Contemporary organisation and
management. Challenges and trends, Wydawnictwo Uniwersytetu Łódzkiego,
Łódź 2020;. Wydawnictwo Uniwersytetu Łódzkiego. [23]
Richter, L., & Haddad, G. (2015). Role of Senior Leadership in Quality Risk
Management. , (4). Journal of Validation Technology 21
Security Scorecard (2021). What is an Information Security Policy and What Should it [1]
Include? Retrieved from https://securityscorecard.com/blog/what- -is-an
information-security-policy-and-what-should- -includeit