Your plan should be a 3.5 page paper (a minimum of three pages of content) to discuss the enterprise Business Continuity and Disaster Recovery plan for the organization that you have chosen.
|
Running head: ENTERPRISE SECURITY RISK MANAGEMENT |
1 |
|
ENTERPRISE SECURITY RISK MANAGEMENT |
5 |
Enterprise Security Risk Management
Name
Course
Tutor
Date
Enterprise Security Risk Management
Introduction
In the previous enterprise security proposal paper, it was clear that many companies now consider information security as their number one concern. We also saw various strategies put in place by several organizations to help them go about the challenges posed by insecurity. Some of the strategies are meant to protect the organization's informational technology from all manner of threats. In contrast, others target mitigation of risks that might scale up the security protocols in place. We focus on the latter by looking at enterprise security risk management by looking at the various parts' enterprise risk assessment plan. Defined as a coordinated set of activities, processes, and methods aimed at supporting the risk control mechanisms by way of identifying, defining, and providing means of ameliorating risks; the Committee of Sponsoring Organizations of the Treadway Commission (COSO) provides a framework that outlines eight standard components making up risk assessment plans as well as a category of for objectives.
The components include the internal environment, objective setting, identifying an event, risk assessment, risk response, control activities, information, and control communication and monitoring. The additional objective categories comprise strategy, operations, financial reporting, and compliance. A risk assessment plan is an essential item in enterprise risk management as it provides a step-by-step approach to combating risks to mitigate them. If left unattended, the risks can affect the organizations’ ability to deliver on set goals and objectives.
Enterprise Risk Management
There are several ways of defining risk. The common one is an event whose chances of occurring fall between zero and one whose impact can be either positive or negative to the organization's course of attaining set goals and objectives. A risk can level one or many effects against the normal running of an enterprise and can as well have one or many causes. On the other hand, risk management is a continuous process that commences simultaneously with a project being undertaken by an organization and concludes at the closure of a project. It encompasses processes such as identification of risks, risk analysis, monitoring, and control. Enterprise risk management processes must always have an objective to accomplish, which sometimes can always be reducing the probability of risk occurrence or mitigating the impact of risk events (Multi-dimensional enterprise-wide security, 2020). Modern risk management planning processes attempt to reduce the likelihood of risk events occurring and mitigate the potential impacts if these risks arise.
The risk identification process often commences before the organization formally starts a project. The expectation is always that the number of identifiable risks increases as the project advances. If a risk is successfully identified, there are a number of projects that ensure. First is to assess the risk to establish the underlying factors such as the probability of the risk occurring during the project, the extent of the impact to the organization's project schedule, cost and scope, and the quality of the product to be delivered.
Risk Assessment Plan
Risk assessment involves determining the chances of a risk occurring and the impact of the occurrence of such a risk to the project being undertaken by an enterprise. By talking of a project does not mean a specific process leading to delivering a product but can also include the day to day operations in an organization to achieve set goals and objects. As initially defined, the risk assessment plan is documentation detailing step by step approaches that define risks, identify them, mitigate, and establish monitoring and controls (Tricomi, 2020). The risk assessment process is essentially a cause and effect analysis since it is based on the event occurrence and impact of the event's occurrence.
Risk assessment can be described as a two-factor process. The first factor is measuring the certainty of the occurrence of a risk (establishing probability), and the second factor is impact estimation (Urban, 2016). The possibility of event occurrence can further be carried in several ways, as shown in the table below.
|
Establishing Risk Event Probability |
||
|
Defining the Probability |
Explanation |
Value |
|
Extremely low frequency |
Almost no chance of happening |
0-1 |
|
Low frequency |
Unlikely to occur A small probability of happening and can only be identified under focused review. |
2 |
|
Normal frequency |
Can sporadically occur Potential issues are identifiable during a focused review |
3 |
|
High frequency |
Frequently occurs. Frequency is limited upon correction of the process. Trained auditors and other experts easily discover discrepancies. The regulators also find it easy identify the risks using guiding policies. |
4 |
|
Extremely high frequency |
High chances of occurring The risk events can occur and re-occur unless a drastic measure is taken to correct the on goings massively. |
5 |
Instead of laboring to come up with a detailed impact estimates, common risk registers classify risks into five rating categories as far as impact of each is concerned. These include category A that comprises catastrophic events resulting from compliance violations, data theft or serious breaches, or inability to validate critical data. Another category is critical risks, which comprise a non-compliance finding process.
Control and monitoring include processes that continuously track, review, adjust, and issue reports on the project's general performance. Project plan, work statement, and budget documents are some of the control and monitoring tools used to manage enterprises' risk.
Conclusion
This article defines risk management as a coordinated set of activities, processes, and methods to support the risk control mechanisms by identifying; defining, and providing ameliorating risks. The article identifies several ways of expressing a risk with the common one being an event whose chances of occurring fall between zero and one whose impact can be either positive or negative to the organization's course of attaining set goals and objectives.
References
Multi-dimensional enterprise-wide security: An action plan. (2020). Retrieved 11 September 2020, from https://searchsecurity.techtarget.com/feature/Multi-dimensional-enterprise-wide-security-An-action-plan
Tricomi, K. (2020): Policies, Procedures, and Standards | BPMInstitute.org. (2020). Retrieved 11 September 2020, from https://www.bpminstitute.org/resources/articles/policies-procedures-and-standards
Urban, M. E. (2016). Enhanced Capabilities for Subcritical Experiments (ECSE) Risk Management Plan (No. LA-UR-16-22988). Los Alamos National Lab.(LANL), Los Alamos, NM (United States).
Zio, E. (2018). The future of risk assessment. Reliability Engineering & System Safety, 177, 176-190.