Intro to IT risk management Flashcards
What is risk?
combination of the probability of an event and its consequence
What factors are considered when evaluating risk?
The mission of the organization, its assets, threat and vulnerability, likelihood, impact
What is governance?
Accountability for protection of the assets of an organization.
Describe corporate governance
system by which organizations are evaluated, directed and controlled.
governance of IT is the system by which the current and future use of IT is evaluated, directed and controlled.
what is the objective of governance?
to enable organizations create value for their stakeholders or to promote value creation. value creation is in turn comprised of benefits realization, risk optimization and resource optimization.
explain the intersection between governance and management?
management focuses on planning, building, running and monitoring activities in alignment with the direction set by the governance body to create value by achieving its objectives
List objectives of risk governance
- establish and maintain a common risk view
- integrate risk management into the enterprise
- make risk aware business decisions
- ensure that risk management controls are implemented and operating correctly
effective risk governance helps ensure that risk management practices are embedded in the enterprise, enabling it to secure optimal risk adjusted return.
what is risk management?
defined as the coordinated activities to direct and control an enterprise with regard to risk
List the risk management considerations
- dependencies on supply chain
- impact of new legislation
- vulnerability to changes in economic or political conditions
what is IT operations and service delivery ?
delivered services fall short of service level agreements
what is IT risk management?
the implementation of a risk strategy that reflects the culture, appetite, and tolerance levels of organizational management; considers technology and budgets; and addresses the requirements of regulation and compliance.
An effective IT risk management strategy is critical to an organization’s ability to effectively and efficiently execute its overall business strategy.
List the steps of the IT risk management process
IT risk identification, IT risk assessment, Risk response and mitigation and risk and control monitoring and reporting.
Describe the relationship between risk and business continuity?
the business continuity function is concerned with the preservation of critical business functions and the ability of the organization to survive an adverse event that may impact the ability of the organization to meet its goals.
through risk management, the organization attempts to reduce all IT risk to an acceptable level. the risk team works with the business continuity team to identify possible threats and put in place the mechanism to detect, contain and recover from an adverse event if it should happen.
Describe the relationship between risk and audit?
the audit function is an important part of corporate governance that provides management with assurance regarding the effectiveness of the control framework.
audits should be conducted by a skilled personnel able to assess risk, identify vulnerabilities, document findings and provide recommendations on how to address audit issues.
Describe the relationship between risk and information security?
IT risk management drives the selection of controls and justifies their initial and continued operation. if the IT risk management activity is not conducted properly, information security controls are most certain to be incorrectly designed, poorly implemented and improperly overstated. each control should be traceable back to a specific IT risk and the risk practitioner should be able to demonstrate the purpose of each control and explain the reasoning behind its selection.