1 / 9100%
People and Risk 1
People and Risk
Dawnne M. Thayer
Liberty University
BMAL 714: Risk Management Process and Practice
Dr. Clifton Thacker
July 26, 2020
Author Note
By submitting this assignment, I attest this submission represents my own work, and
not that of another student, scholar, or internet source. I understand I am responsible for
knowing and correctly utilizing referencing and bibliographical guidelines.
People and Risk 2
Abstract
There is a close connection between people, risk and security. This paper will discuss that relationship
and how the human resource factor is impacted by the effectiveness of the risk management plan. The
student will select a specific industry, in this case that will be the information technology industry, and
then assess this relationship. The student will build a risk management plan and determine the
effectiveness of said plan in the pertinence toward the human resource division of the chosen industry.
The research will be supported by a minimum of five scholarly sources in addition to the texts and the
Bible. The student will ensure biblical integration by addressing a couple of the more prominent risk
managers in the Bible and how their management of risk effected the people they were charged to lead.
In using the scholarly articles, the student will support the importance of information technology (IT) and
the risks the human factor brings to the industry. The student posits that people drive and mitigate risk
in this field. While there are no numbers to support a percentage on either side, it is reasonable to
believe that people can be trusted for the most part, but organizations definitely need to have a security
program in place to monitor information as it comes and goes to ensure no information is being
accessed inappropriately or that it is falling into the wrong hands. The risk management plan created
here will support this and provide a map to help establish such a system.
People and Risk 3
Introduction The Information Technology Industry
The information technology industry is crucial in the business world today. Everything revolves
around technology and the access to information it provides. Using this technology businesses have
been able to cut costs, conduct more in-depth market research and build rapport with customer and
clients thusly forging stronger relationships. While technology offers great rewards and opportunities, it
also presents new risks and concerns for all who take advantage. Businesses facing these risks must
develop security metrics and techniques to monitor potential threats and attacks. By developing such a
plan, the firm can assess the probability of attacks and the success of such attacks on the information the
organization holds. This plan can also present the probable cost of any such successful attack. Once this
information is known, leadership must choose the right countermeasures to offset the probability of
these attacks. Leadership, when conducting research, must consider these attacks can come from
outside the organization or right within by their own employees.
Fariborz et al. (2005, p. 203) posits a primary reason for engaging in e-commerce is the potential
loss of assets and privacy as a result of system breaches. It is not, however, only the assets and privacy a
company risks losing. Organizations also risk damage to the established reputation and leads to vast
repercussions for the firm and the IT industry meaning years of recovery if any at all. Recovery from a
security breach takes many years if a firm can recover at all and the costs of such recovery would be
astronomical for some organizations. A security breach could mean the end of an organization so the
importance of protecting information and safeguarding all the organizations holds is of utmost
importance when conducting business in the world of e-commerce.
There are things a company must consider when building a risk management plan regarding IT.
Intellectual property, networks, databases and encryption are just a few. When considering all of these,
the focus must be on people. People are the one who will commit acts against any and all of these areas
of probable attacks. Employees especially have opportunity to commit such acts and are more likely to
People and Risk 4
have the ability to cover their tracks than would someone outside the firm. This is especially true if the
violator is a member of the IT team directly. Kerr (2014, p. 336) reinforces the idea that threats change
as opportunities and rewards change to create a gain for those who might consider committing such an
offense. Another thing a company should do when considering countermeasures is to manage
information security rather than just imposing IT security. These measures focus on people, processes,
information and IT. The newest worldwide standards of information security places more focus on
insider threats as internal attacks are more common than external attacks.
Insider threats are caused by employees, leadership or contractors that capitalize on the
weaknesses in systems for a gain be it financial or otherwise. The leadership team is ultimately
accountable for protecting all assets belonging to the organization. These leaders must establish,
according to Humphreys (2008, p. 8), risk management process and an effective system of internal
controls to support the process. When it comes to information security (IS) consideration should be
given to known risks regarding the assets. All information security risks should be identified and assessed
to implement a system of controls. This should be followed up with perpetual monitoring and
improvements to these controls when deemed ineffective.
Smith (1989, p. 1) researches people and risk. In this research there is a conclusion drawn that
little regard is given to people risks and what motivates people to do the things they do. There is far too
much apathy toward people and the risks presented regarding information security. The fallibility created
by apathy and ignorance reveals traditional approaches to information security are not enough. It seems
every day there are new attacks discovered and new ways to implement these attacks so staying on top
of information security is a challenging prospect. Mitigating the risks involved must be at the forefront of
organizational thinking. Because of the rapidity of new ways to attack information security there is a
need for constant education of the staff. Sollars (2016, p. 4) discusses the need for a new approach. The
first thing covered is the education of staff and getting the employees on board to follow the rules and
People and Risk 5
alert leadership over suspicious activity. Sollars posits employees should be the first line of defense
rather than being the weakest link or the greatest threat. This presents a new mindset of not only the
nature of the risk but also the loss it presents. Another thing organizations need to do in a new approach
is to consider all risks, not just those to information security. This is taking an overall look at the provision
of security being offered. It is a complicated process and spending more money on security measures
does not guarantee better security or the best security. Spending more only adds to the complexity of
the problem. It is more beneficial to spend the time needed to assess risks, prioritize them and continue
to work toward the outer barriers to set up a system that offers security at all levels of the organization.
This safeguards all assets not just information security.
Risk Management Plan
People and Risks Potential Impact Mitigations
Inadequate security training and
awareness
Employees could unknowingly
provide the ability to execute
successful attacks. Lack of training
means employees do not know to
process in securing information
creating weakness in the system
controls. They might insert a
malicious USB drive, hold a door open
for someone who may not work
there, open unrecognized emails and
click on links, and they might lose or
misuse their id badges.
Develop a rigid training
program for security
awareness and
periodically send tests
randomly to employees
throughout the
organization to see who is
aware and who needs
further training or even
dismissal for failure to
comply. The training
should be adequate in
addressing the insecure
behavior of the staff.
Training should be
perpetual and should be
done annually after the
initial onboard training.
Insufficient identity verification
or failed background checks
People are the weakest link of any
security posture. Background checks
and identification validation are
crucial to managing the risks involved.
As information clearance levels
increase consideration must be made
to segregate tasks so no one
individual has access to all
information all the time. Dont give
Ensure proper background
procedures on conducted
on all new hires. Before
providing access to high
security information, be
sure proper authorization
and authentication
processes are in place.
This will allow for
People and Risk 6
one person the keys to the palace. verification of who is
asking for the information
and confirms said party is
authorized to access it, it
also tracks who is asking
for what, how often, and
from where.
Inadequate security policy Inadequate policies lead to breaches.
Policies need to be the foundation of
all operational requirements and
practices.
Security policies
appropriately encompass
all facets of creating a
secure environment.
Inadequate privacy policy Inadequate privacy policies lead to
the exposure of sensitive information
including personal information of
employees, customer, vendors and
others leading to operational and
security risks. Irreparable reputation
damage can result as well.
Privacy policy adequately
encompass all facets of
safeguarding access to
private information.
Inadequate security oversight
by management
Management must own the security
program. If management does not
take ownership for this program, they
cannot enforce the repercussions of
the program being compromised or
abused.
A senior manager should
be assigned responsibility
of the program. This
person should be
empowered to make
decisions to improve and
enforce the policy.
Improper revocation of access Failing to revoke access when
someone no longer needs it could
result in unauthorized access.
Make sure employees
have access to only the
information and systems
they need when they
need it in order to do the
job as assigned. Revoke all
access for terminated
employees ahead of
termination notice to
minimize a retaliatory
attack.
Activity/Security Control Rationale
Perpetual risk assessment and mitigation to include threat
analysis and vulnerability review.
Maintain a full view of the
organizations security controls
as opposed to just the threats
facing the organization.
Control, monitor and track all access to assets. Revoke unauthorized and
prevent unauthorized access to
assets and detect unauthorized
access and enforce
People and Risk 7
repercussions of unauthorized
access.
Protected assets must be disposed of properly or reassigned
properly.
Make sure all assets are
reassigned or disposed of in a
secure nature preventing
unknowingly exposing
information to unauthorized
persons or entities.
Develop a secure change control process as well as
management configuration processes.
Be sure changes to the system
do not negatively impact
security controls in order to
protect assets.
Develop breach handling policies, plans, procedures and
accountabilities (repercussions).
Be ready to act rapidly and
efficiently to avoid or contain
damage after a breach occurs.
Have a contingency plan and procedure Be ready to act rapidly and
efficiently to recover lost assets
and continue business as usual
after a breach.
Train employees in breach handling and contingency plans Be sure employees responsible
for responding to a breach are
fully educated and trained on
the response plans and can
implement them under a great
deal of pressure and stress.
Conclusion
There are many examples of great risk managers in the Bible. In Nehemiah 1 Nehemiahs brother
tells of the wall of Jerusalem having been torn down and the gates destroyed by fire. Nehemiah seeks
the kings help in the task of rebuilding the wall. Nehemiah covertly watches the wall at night and wisely
avoids adversity from those who would present opposition. Joseph was a man of unshakable faith and
wisdom. God warned Pharaoh of the famine. God enacts several things allowing for Joseph to be
removed from prison and to proactively manage the risk of surviving Egypt. A prudent man forseeth the
evil, and hideth himself: but the simple pass on, and are punished(The Holy Bible, Proverbs 22:3, King
James Version). This passage states that a prudent person see danger and take precautions where a
simpleton goes on without acknowledging the presence of danger and suffers the consequences. It is
foolish not to recognize risk. A smart person takes precautions to proactive address risk rather than
People and Risk 8
being reactive. If an organization or person does not acknowledge risk and use precautionary measures,
they face the consequences by way of lost assets. There is a solid biblical support for proactive handling
of risk management through both prayer and action. Both should be applied professionally and
personally.
Many risks with information security and people can be addressed in the onboarding process.
Whether it is an employee, a contractor, a vendor or otherwise, adding a security process induction to
the onboarding process to avoid situations that could lead to a breach inadvertent or not. No matter
how sophisticated a security plan may be, an organization must remember it is the junior staff members
who have more network access points than do senior members. These areas include reception, phones,
network monitoring, and others. All facets must be considered no matter how simple they may seem;
like locking all monitors and laptops when not in use. Many advancements have come forth recently to
increase security protection like the two-factor authentication. Employees have less effort in logging in
but allows for the reporting of suspicious activity on the organizations network.
A big benefit to these simple tools is the empowerment of employees. The organization makes
the staff feel that they are key to the security policy and play a crucial role in safeguarding business-
critical assets. Most company breaches could be avoided if organizations engaged the employees and
used a more inclusive way of thinking about information security and protecting said business-critical
assets. Having an information security risk management plan is a crucial element in the maturing of the
capabilities. If such a strategy is implemented it will prove invaluable and will show a decrease in the
number of breaches and an increase in the savings in the costs of losses an organization would face if no
such strategy was in place.
References
People and Risk 9
Farahmand, F., Navathe, S. B., Sharp, G.P. & Enslow, P.H. (2005). A management perspective on risk of
security threats to information systems. Information Technology and Management, 6, 203-225.
https://link-springer.com.ezproxy.liberty.edu/content/pdf/10.1007/s10799-005-5880-5.pdf
Humphreys, E. (2008). Information security management standards: Compliance, governance and
risk management. Information Security Technical Report, 13(4), 247-255.
https://doi.org/10.1016/j.istr.2008.10.010
Kerr, J. (2014). The art of risk management: The crucial role of the global art insurance industry in
enabling risk and security. Journal of Risk Research, 75, 547-559.
https://doi.org/10.1016/j.chb.2017.05.038
Smith, M. (1989). The people risks. Computer Law & Security Review, 4(6), 2-6.
https://doi.org/10.1016/0267-3649(89)90002-2
Sollars, M. (2016). Risk-based security: Staff can play the defining role in securing assets. Network
Security, 9, 9-12. https://doi.org/10.1016/s1353-4858(16)30087-3
The Holy Bible. Authorized King James Version. (1798/2011). Thomas Nelson Inc.
Wright, L. (2017). People, Risk, & Security: How to prevent your greatest asset from becoming your
greatest liability. Palgrave McMillan
Powered by TCPDF (www.tcpdf.org)
Students also viewed