PEOPLE AND RISK MANAGEMENT 1
Kevin Lacey
BMAL 714
People and Risk Management
4/18/21
PEOPLE AND RISK MANAGEMENT
2
Abstract
There is a very particular association between individuals, risks, and security. This paper will
examine that relationship and how the human asset factor is affected by the viability of the risk
management plan. The understudy will choose a particular industry, for this situation that will be
the data innovation industry, and afterward evaluate this relationship. The understudy will pick a
risk management plan and decide the effectiveness of said plan in the relevance toward the
information technology industry. The scholarly research will be upheld by at least five academic
sources along with the writings and the Bible. The student will guarantee scriptural incorporation
by incorporating two or three the more unmistakable risk managers in the Bible and what their
way of risk management meant for individuals they were charged to lead. In utilizing the
insightful articles, the student will stress the significance of information technology (IT) and the
dangers the human factor brings to the business. The student sets that individuals drive and
moderate risks in this field. While there are no numbers to support a percentage on one or the
other side, it is sensible to accept that individuals can be trusted generally, however associations
unquestionably need to have a security program set up to screen data as it goes back and forth to
guarantee no data is being assessed improperly or that it is falling into some unacceptable hands.
The risk management plan made here will uphold this and give a guide to help build up such an
operation.
Introduction – The Information Technology Industry
The data innovation industry is vital in the business world today. Everything spins around
innovation and the accessibility to data it gives. Utilizing this technology, organizations have had
the option to reduce expenses, direct more in depth statistical surveying and foster compatibility
with clients and customers hence manufacturing more grounded connections. While innovation
PEOPLE AND RISK MANAGEMENT
3
offers incredible prizes and openings, it likewise presents new dangers and worries for all who
exploit it. Organizations confronting these dangers should create security measurements and
methods to screen for possible dangers and assaults. By growing such an arrangement, the firm
can survey the likelihood of assaults and the accomplishment of such assaults on the data the
company holds. This arrangement can likewise introduce the plausible expense of any such
threat. When this data is known, management should pick the correct countermeasures to
counteract the likelihood of these assaults. Administration, when doing research, should consider
these dangers that can emerge out of outside the association or right inside by their own workers.
Fariborz et al. (2005, p. 203) posits a primary reason for engaging in e-commerce is the potential
loss of assets and privacy as a result of system breaches. It isn’t, however, just the resources and
security an organization risks losing. Associations additionally risk harm to the reputation and
prompts tremendous repercussions for the firm and the IT business meaning long periods of
recuperation if any whatsoever. Recuperation from a security breach requires numerous years if a
firm can recuperate at all and the expenses of such recuperation would be egregious for certain
associations. A security break could mean the demise of an association so the significance of
protecting data and defending every one of the associations holds is of most extreme significance
when leading business in the realm of online business.
There are things an organization should consider when constructing a risk management plan with
respect to IT. Licensed technology, organizations, data sets and encryption are only a couple to
be considered. While considering these, the emphasis should be on individuals. Individuals are
the people who will submit acts against any of these spaces of likely assaults. Workers
particularly have freedom to submit such demonstrations and are able to cover their tracks better
than somebody outside the firm. This is particularly obvious if the violator is an individual from
PEOPLE AND RISK MANAGEMENT
4
the IT group. Kerr (2014, p. 336) builds up the possibility that risks change as promising
circumstances and prizes change to make an increase for the individuals who should think about
committing such an offense. Something else an organization ought to do while considering
countermeasures is to oversee data security as opposed to simply forcing IT security. These
actions center on individuals, processes, data and IT. The most up to date overall norms of data
security puts more spotlight on insider dangers as inner attacks are more normal than outside
attacks.
Insider dangers are brought about by workers, administration or workers for hire that benefit
from the shortcomings in operations for a profit, be it monetary or something else. The
management group is eventually responsible for securing all resources that have a spot with the
association. These pioneers should set up, as indicated by Humphreys (2008, p. 8), risk
management and a compelling arrangement of internal controls to help the system. With regards
to information security (IS) thought ought to be given to realized dangers in regards to the
resources. All data security dangers ought to be distinguished and evaluated to carry out an
arrangement of controls. This ought to be circled back to perpetual checking and enhancements
to these controls when considered ineffective.
Smith (1989, p. 1) explores individuals and dangers/risks. In this research there is an end drawn
that little respect is given to individuals risks and what propels individuals to do the things they
do. There is immeasurably an excessive amount of unresponsiveness toward individuals and the
dangers introduced with respect to data security. The fallibility made by carelessness and
obliviousness uncovers customary ways to deal with data security are not adequate. It appears to
be each day there are new dangers found and better approaches to carry out these assaults so
constantly looking over data security is a difficult task in itself. Alleviating the dangers implied
PEOPLE AND RISK MANAGEMENT
5
should be at the bleeding edge of authoritative reasoning. In view of better approaches to attack
data security there is a requirement for steady schooling of the staff. Sollars (2016, p. 4)
examines the requirement for another methodology. The principal thing covered is the schooling
of staff and getting the workers on board to observe the guidelines and ready administration over
dubious movement. Sollars feels like workers ought to be the principal line of protection as
opposed to being the most fragile connection or the biggest danger. This presents another
mentality of the idea of the danger as well as the misfortune it presents. Something else
associations need to do in another methodology is to think about all dangers, not only those to
data security. This is investigating the arrangement of safety being advertised. It is a muddled
interaction and spending more cash on safety efforts doesn’t ensure better security or the best
security. Spending all the more just adds to the intricacy of the issue. It is more useful to invest
the energy expected to analyze risks, focus on them and keep on pursuing the external
boundaries to set up a framework that offers security at all levels of the association. This shields
all resources not simply data security.
Risk Management Plan
People and Risks Potential Impact Mitigations
Inadequate security training
and awareness
Employees could
unknowingly provide the
ability to execute successful
attacks. Lack of training
means employees do not know
to process in securing
information creating weakness
Develop a rigid training
program for security
awareness and periodically
send tests randomly to
employees throughout the
organization to see who is
aware and who needs further
PEOPLE AND RISK MANAGEMENT
6
in the system controls. They
might insert a malicious USB
drive, hold a door open for
someone who may not work
there, open unrecognized
emails and click on links, and
they might lose or misuse their
id badges.
training or even dismissal for
failure to comply. The training
should be adequate in
addressing the insecure
behavior of the staff. Training
should be perpetual and
should be done annually after
the initial onboard training
Inadequate identity
verification or failed
background checks
Inadequate policies lead to
breaches. Policies need to be
the foundation of all
operational requirements and
practices.
Security policies appropriately
encompass all facets of
creating a secure environment.
Inadequate privacy policy Inadequate privacy policies
lead to the exposure of
sensitive information
including personal
information of employees,
customer, vendors and others
leading to operational and
security risks. Irreparable
reputation damage can result
as well.
The privacy policy adequately
encompasses all facets of
safeguarding access to private
information.
Inadequate security oversight
by management
Management must own the
security program. If
A senior manager should be
assigned responsibility of the
PEOPLE AND RISK MANAGEMENT
7
management does not take
ownership for this program,
they cannot enforce the
repercussions of the program
being compromised.
program. This person should
be empowered to make
decisions to improve and
enforce the policy.
Improper revocation of access Failing to revoke access when
someone no longer needs it
could result in unauthorized
access
Make sure employees have
access to only the information
and systems they need when
they need it in order to do the
job as assigned. Revoke all
access for terminated
employees ahead of
termination notice
Insufficient identity
verification or failed
background checks
People are the weakest link of
any security posture.
Background checks and
identification validation are
crucial to managing the risks
involved. As information
clearance levels increase
consideration must be made to
segregate tasks so no one
individual has access to all
information all the time.
Ensure proper background
procedures on conducted on
all new hires. Before
providing access to high
security information, be sure
proper authorization and
authentication processes are in
place. This will allow for
verification of who is asking
for the information and
confirms said party is
PEOPLE AND RISK MANAGEMENT
8
authorized to access it, it also
tracks who is asking for what,
how often, and from where.
Activity/Security Control Rationale
Perpetual risk assessment and mitigation to
include threat analysis and vulnerability
review.
Maintain a full view of the organizations
security controls as opposed to just the threats
facing the organization.
Control, monitor and track all access to assets Revoke unauthorized and prevent unauthorized
access to assets and detect unauthorized access
and enforce repercussions of unauthorized
access.
Protected assets must be disposed of properly
or reassigned properly
Make sure all assets are reassigned or disposed
of in a secure nature preventing unknowingly
exposing information to unauthorized persons
or entities.
Develop a secure change control process as
well as management configuration processes.
Be sure changes to the system do not
negatively impact security controls in order to
protect assets.
Develop breach handling policies, plans,
procedures and accountabilities
(repercussions).
Be ready to act rapidly and efficiently to avoid
or contain damage after a breach occurs
Have a contingency plan and procedure Be ready to act rapidly and efficiently to
recover lost assets and continue business as
usual after a breach.
Train employees in breach handling and Be sure employees responsible for responding
PEOPLE AND RISK MANAGEMENT
9
contingency plans to a breach are fully educated and trained on
the response plans and can implement them
under a great deal of pressure and stress.
Conclusion
There are numerous instances of extraordinary risk management leaders in the Bible. In
Nehemiah 1 Nehemiah's sibling recounts the wall of Jerusalem having been destroyed and the
doors annihilated by fire. Nehemiah looks for the ruler's assistance in the assignment of
modifying the wall. Nehemiah secretly watches the wall around evening time and astutely
dodges misfortune from the individuals who might introduce resistance. Joseph was a man of
steadfast confidence and intelligence. God cautioned Pharaoh of the famine. God orders a few
things taking into consideration Joseph to be released from jail and to proactively deal with the
danger of surviving Egypt. "A reasonable man forseeth the insidiousness, and hideth himself: yet
the simple pass on, and are punished" (The Holy Bible, Proverbs 22:3, King James Version).
This entry expresses that a reasonable individual sees danger and avoids potential risk where a
blockhead goes on without recognizing the presence of threat and endures the outcomes. It is
absurd not to foresee dangers. A shrewd individual plays it safe to be proactive instead of being
responsive. On the off chance that an association or individual doesn't recognize dangers and
utilize careful steps, they face the results via lost resources. There is a strong scriptural help for
proactive treatment of dangers the executives through both supplication and activity. Both ought
to be applied expertly and actually. Numerous dangers with data security and individuals can be
tended to in the on-boarding cycle. Regardless of whether it is a worker, a project worker, a
merchant or something else, adding a security cycle enlistment to the on-boarding interaction to
PEOPLE AND RISK MANAGEMENT
10
keep away from circumstances that could prompt a breach unintentional or not. Regardless of
how complex a security plan might be, an association should remember it is the lesser staff
individuals who have more organization access than do senior individuals. These areas
incorporate gathering, telephones, network checking, and others. All features should be respected
and viewed as regardless of how basic they may appear; like locking all screens and PCs when
not being used. Numerous advancements have approached as of late to expand security assurance
like the two-factor verification. Representatives have less effort on signing in yet take into
consideration the revealing of dubious activity on the associations network. A major advantage to
these basic apparatuses is the strengthening of network. The association causes the staff to feel
that they are vital to the security strategy and assume a pivotal part in defending business basic
resources. Most organizational breaches could be kept away from if associations drew in the
representatives and utilized a more comprehensive perspective about data security and ensuring
said business-basic resources. Having a data security risk management plan is a pivotal
component in the developing of the capabilities. In the event that such a procedure is carried out
it will demonstrate importance and will show a decrease in the quantity of breaches and an
expansion in the investment funds.
PEOPLE AND RISK MANAGEMENT
11
References
Farahmand, F., Navathe, S. B., Sharp, G.P. & Enslow, P.H. (2005). A management perspective on
risk of security threats to information systems. Information Technology and Management,
6, 203-225. https://link-springer.com.ezproxy.liberty.edu/content/pdf/10.1007/s10799-
005-5880-5.pdf
Humphreys, E. (2008). Information security management standards: Compliance, governance
and risk management. Information Security Technical Report, 13(4), 247-255.
https://doi.org/10.1016/j.istr.2008.10.010
Kerr, J. (2014). The art of risk management: The crucial role of the global art insurance industry
in enabling risk and security. Journal of Risk Research, 75, 547-559.
https://doi.org/10.1016/j.chb.2017.05.038
Smith, M. (1989). The people risks. Computer Law & Security Review, 4(6), 2-6.
https://doi.org/10.1016/0267-3649(89)90002-2
Sollars, M. (2016). Risk-based security: Staff can play the defining role in securing assets.
Network Security, 9, 9-12. https://doi.org/10.1016/s1353-4858(16)30087-3
The Holy Bible. Authorized King James Version. (1798/2011). Thomas Nelson Inc.
PEOPLE AND RISK MANAGEMENT
12
Wright, L. (2017). People, Risk, & Security: How to prevent your greatest asset from becoming
your greatest liability. Palgrave McMillan