Information Technology Security. Advice from Experts

Risk management is about risk mitigation for the most part. This may be done by reducing the impact and/or by reducing the probability of the risk occurring. To do this, various controls defined by a hierarchy of controls are applied. This hierarchy of controls provides a common terminology used to describe risk management. The success of risk management depends on its ability to implement changes across all of IT in the areas of policy, process, management practices, procedures and standards. To do this, establish a common understanding of how terms are used throughout the business.

There are three key elements associated with mitigating risks. Change can occur in people, processes, or technology.

Категории