Risk management is a very complex and intricate concept, but I will do my
best to unravel the mystery for you all here. Let’s start by asking, what
exactly is risk management? Risk management is the process of identifying,
assessing, and controlling threats to an organization's capital and earnings.
(Tucci, n.d) When implementing a risk management framework at Padgett-
Beale, we first need to discuss some foundational concepts.
Those initial concepts include several levels that create a solid structure
that support our company. The first level discusses the organization and the
second expresses the business process. Generally, these stages are closely
linked together. Here are five topics that are highlighted in the NIST “Risk
Management Framework for Information Systems and Organizations
publication.
• Assigning roles and responsibilities for organizational risk management
processes;
• Identifying key stakeholders (internal and external to the organization)
that have an interest in the information system;
• Identifying and prioritizing assets (including information assets);
• Understanding the potential adverse effects on individuals;
• Identifying and prioritizing security and privacy requirements. (NIST,
2018)
The third and final stage is the information system. In this stage the
approach is focused on risk decisions regarding the mission or business
specified by the organization.
Next, we’ll talk about the seven steps that make the system of risk
management framework.
1. Prepare – Prepare to execute the RMF from an organization- and a
system-level perspective by establishing a context and priorities for
managing security and privacy risk.
2. Categorize – the system and the information processed, stored, and
transmitted by the system based on an analysis of the impact of loss.
3. Select – an initial set of controls for the system and tailor the controls
as needed to reduce
risk to an acceptable level based on an assessment of risk.
4. Implement - the controls and describe how the controls are employed
within the system and its environment of operation.
5. Asses - the controls to determine if the controls are implemented
correctly, operating as intended, and producing the desired outcomes
with respect to satisfying the security and privacy requirements
6. Authorize - the system or common controls based on a determination
that the risk to organizational operations and assets, individuals, other
organizations, and the Nation is acceptable.
7. Monitor - the system and the associated controls on an ongoing basis
to include assessing control effectiveness, documenting changes to
the system and environment of operation, conducting risk
assessments and impact analyses, and reporting the security and
privacy posture of the system. (NIST, 2018)
Before implementing RMF the organization should consider the differences
between requirements and controls. So, what’s the difference?
Requirements generally apply to policy and laws; meanwhile, controls can
be described as safeguards and protections geared towards the security of
the organization. The organization is also in charge of creating controls that
can best suit their needs. The needs can be made in technical,
administrative, or physical forms. In addition to controls, another aspect of
RMF is supply chain risk management.
In 2020 we had seen firsthand the hardships and headaches of the supply
chain process being affected by a global pandemic. Many businesses small
and large had troubles making their products and meeting customer
expectations in various ways. Some didn’t meet deadlines, while others
simply did not have certain materials on hand to assemble their products.
RMF tackles this concept by considering several of the issues that should be
addressed when covering the topic of supply chain. Primarily, the
organization needs to build trust with all the parties involved. The trust
accounts for stakeholders determining what can be established as a priority
or what can be a secondary priority. When developing a plan, RMF should
address the systems or services that are at risk to supply chain issues.
In conclusion, Padgett-Beale needs to establish a risk management
framework in which to work alongside all entities involved. The RMF would
be able to establish certain points of contact, policies, procedures, and
technical controls that can help mitigate threats and major concerns that
jeopardize the hotel’s assets, systems, and personnel. Thank you and have a
productive Padgett-Beale day.
References:
Tucci, Linda. (n.d.) “What is risk management and why is it important?”
TechTarget
. https://searchcompliance.techtarget.com/definition/risk-
management
NIST. (2018) “Risk Management Framework for Information Systems and
Organizations”
NIST
.
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-
37r2.pdf