preview

A Short Note On Risk Assessment And Management

Better Essays

In present scenario every company has an objective, in this digital era, companies uses automated information technology system to process their information for better support. Risk assessment and management plays an important role in protecting company’s information assets, and therefore its objectives. An effective risk assessment process is a significant factor of a successful IT security program. The major goal of a company’s risk assessment process should be to protect the companies and its abilities to perform their objectives.
Learning Objective of this Chapter

Upon completion of this chapter you will be able to understand:
• Risk Analysis and Risk Management,
• Steps to analyze the risk,
• Risk categorization and cost/benefit ratio,
• Vulnerability and threats.
1. Introduction
Risk can be defined as the combination of the probability of an event and its consequences (ISO/IEC Guide 73). The dictionary defines Risk as someone or somewhat that create hazards. Information security professionals realize that nothing ever run smoothly for a long time. Any sorts of internal or external hazard or risk can cause a well running organization to lose critical data to its competitors, miss deadlines or suffer embarrassment. Risk is the probability that an asset will suffer an event of exploitation determined from various factors, the ease of executing an attack, the attacker’s motivation and resources, a system’s existing vulnerabilities, and the cost or impact in a

Get Access