Running head: RISKS MANAGEMENT 1
Risk Management
Name
Institution
Professor
Course
Date
RISK MANAGEMENT 2
Organizations endeavors to identify security threats to the physical and digital assets as
well as their interlinkages (Band et al., 2015). To enhance threat identification role, the
organization ought to understand the user types including their roles. This helps the organization
to be able to diagnose internal or external security threats be it natural or human-related
(Knowles et al., 2015).
Once threats are identified, the organization develops protection means that safeguards
against potential threats. Some security domains in information systems of an organization are
complicated to the workforce, which requires the IT department to communicate various
suspicious programs (DiMase et al., 2015). For instance, a staff could click on to a suspicious
email link that surveys the activities within his or her computer, which threatens the security of
the organization’s information system. This requires communicating all those domains that direct
workers are in a position to protect the security of the information system (Peltier, 2016).
Detection of the system threats is important because it helps to determine the
cybersecurity occurrence. The organization uses this method to continuously monitor network
thus preventing potential cyber incidents (Joshi & Singh, 2017). However, in case of a security
breach, the organization requires to respond and determine the impact, which helps to perform
that, helps to nullify the security risk. Consequently, it follows to recover the system as well as
restoring to its default setting. This requires an appropriate restoration plan with external
assistance and proper backup (Shameli-Sendi, Aghababaei & Cheriet, 2016).
RISK MANAGEMENT 3
Response
The student indicates how organizations coordinate the four elements of information
systems including people, technology, data, and processes to mitigate, monitor and minimize
security risks. To manage security, organizations conduct risk management that involves
identification, evaluation, assessment, and risk prioritization. Identifying threats is encountering
security threats capable of causing loss of financial and intellectual assets. Upon identifying
threats, the organization assesses system vulnerability to all IT infrastructure, software, and
hardware components.
The main functions used to solve the vulnerability issue include configuration and use of
better infrastructures that help to minimize risks. Moreover, organizations employ security
controls which helps to reduce the risks to acceptable levels. Additionally, physical controls help
to restrict access to various places within an organization that contains sensitive and financial
information. Organizations use infrastructures such as cable locks, cameras, security guards,
which restricts unauthorized people from accessing places with sensitive information. I concur
with the use of PCI DSS payment methods such as MasterCard and Visa with encrypted
information as a way to safeguard sensitive financial information. The methods that these options
use such as passwords, data encryption, and host-based firewalls make the online payment
reliable and ease the method of payments that address urgency in business.
RISK MANAGEMENT 4
References
Band, I., Engelsman, W., Feltus, C., Paredes, S. G., & Diligens, D. (2015). Modeling Enterprise
Risk Management and Security with the ArchiMate®.ALanguage, the Open Group.
DiMase, D., Collier, Z. A., Heffner, K., & Linkov, I. (2015). Systems engineering framework for
cyber physical security and resilience.AEnvironment Systems and Decisions,A35(2), 291-
300
Joshi, C., & Singh, U. K. (2017). Information security risks management framework–A step
towards mitigating security risks in university network.AJournal of Information Security
and Applications,A35, 128-137.
Knowles, W., Prince, D., Hutchison, D., Disso, J. F. P., & Jones, K. (2015). A survey of cyber
security management in industrial control systems.AInternational journal of critical
infrastructure protection,A9, 52-80.
Peltier, T. R. (2016).AInformation Security Policies, Procedures, and Standards: guidelines for
effective information security management. Auerbach Publications.
Shameli-Sendi, A., Aghababaei-Barzegar, R., & Cheriet, M. (2016). Taxonomy of information
security risk assessment (ISRA).AComputers & Security,A57, 14-30.