Enterprise Risk Management

profilevars
Excel.xlsx

Sheet1

RISK EVENT PROBABILITY IMPACT Pros/Cons PROPOSED MITIGATION PLAN RISK LEVEL RISK DECISION
Device (laptop, phone) that contains proprietary data is stolen. High huge loss of competitive advantage, bad media exposure pro- might help to discover hidden vulnerabilities in the employees. Cons-employees may oppose mitigation techniques prevent employees from taking work laptops home. Provide locks for the laptops. high accept
internal network break-in from outside medium disrupt system, loss of vital data pro-will lead to reduced external attacks once it is solved. Cons- implementation costs use of firewalls and other network intrusion detection systems medium transfer
virus worm or trojan infection medium restoration is needed, productivity loss pro-identifies security loopholes allowing for mitigation against them. Cons-yearly cost for antivirus install kaspersky antivirus (Grachev, , & Batenin, 2013). medium accept
source code stolen by external attacker or insider medium loss of competitive advantage cons- could lead to corporate espionage use authorization technique to prevent unauthorised members from accessing low accept
denial of service attacks medium productivity loss, system restoration might be needed pros- presence of compensation controls will allow for the reassignment of resources to other high risk areas. Cons-could lead to customer loss use of compensation controls. For example the use of firewalls medium transfer
data security breach for personal, financial and/or customer data medium-low some amount of bad media exposure, loss of customers, possibility of lawsuits Cons- underestimating this vulnerability could lead to increased breaches and unauthorized access use of biometric authentication techniques low avoid
prolonged IT outage low high disruption, productivity loss, system restoration NA provide secondary power options e.g. CPUs medium transfer
pirated software, music or movies used within Code Galore low fines, reputation loss pros-there are less chances of unauthorized access to files in the system. Cons-if mitigation technique fails it could be detrimental blocking of certain websites low accept
attack against others initiated by Code Galore employee low negative media exposure, fines, lawsuits cons-possible destruction of property introduction of organizational behavior policies low accept
data extrusion through interception of wireless signals medium forbbiding policies against use of wireless media in sending confidential and proprietary information without authorization pros- curb any attempts at destroying companies integrity NA medium mitigate
sabotage of source code medium loss of productivity pros-integrity of source code is protected. cons- failure to address this issue could lead to competitor gaining access to the source code leading to loss of competitive advantage (Flynn, Clark, Moore, , Collins, Tsamitis, Mundie, & McIntire, 2013). use authorization only for top notch members of the organization medium mitigate
Flynn, L., Clark, J., Moore, A. P., Collins, M., Tsamitis, E., Mundie, D., & McIntire, D. (2013, October). Four insider IT sabotage mitigation patterns and an initial effectiveness analysis. In Proceedings of the 20th Conference on Pattern Languages of Programs (pp. 1-19). Grachev, V. V., & Batenin, V. A. (2013). U.S. Patent No. 8,424,093. Washington, DC: U.S. Patent and Trademark Office.