INFORMATION ASSURANCE
RISK MANAGEMENT
JOEL C. FABILLARAN, MIT
WHAT IS RISK MANAGEMENT?
RISK MANAGEMENT
 Risk Management is the process of determining
the extent to which an entity is threatened; that
is, determining the likelihood of potential adverse
circumstances or events and the resulting harm to
or impact on organizational operations,
organizational assets, individuals, other
organizations, and the nation.
WHAT IS IA RISK MANAGEMENT?
IA RISK MANAGEMENT
 Information Assurance (IA) Risk Management is a
process employed by an organization to achieve and
maintain an acceptable level of IA risk. It provides a
framework for decision-makers to continuously
evaluate and prioritize IA risks to accept or
recommend strategies to remediate or mitigate
those risks to an acceptable level.
RISK MANAGEMENT PROCESS
RISK MANAGEMENT PROCESS
 BACKGROUND PLANNING
 ASSET ANALYSIS
 THREAT ANALYSIS
 VULNERABILITY ANALYSIS
 RISK IDENTIFICATION
 RISK ANALYSIS
 RISK TREATMENT
 MONITORING RISK
INTEGRATION WITH OTHER
MANAGEMENT PRACTICES
 Budgeting
 Business Planning
 Internal Audit
 Periodic Reporting

Information Assurance Risk Management.pptx

  • 1.
  • 2.
    WHAT IS RISKMANAGEMENT?
  • 3.
    RISK MANAGEMENT  RiskManagement is the process of determining the extent to which an entity is threatened; that is, determining the likelihood of potential adverse circumstances or events and the resulting harm to or impact on organizational operations, organizational assets, individuals, other organizations, and the nation.
  • 4.
    WHAT IS IARISK MANAGEMENT?
  • 5.
    IA RISK MANAGEMENT Information Assurance (IA) Risk Management is a process employed by an organization to achieve and maintain an acceptable level of IA risk. It provides a framework for decision-makers to continuously evaluate and prioritize IA risks to accept or recommend strategies to remediate or mitigate those risks to an acceptable level.
  • 6.
  • 7.
    RISK MANAGEMENT PROCESS BACKGROUND PLANNING  ASSET ANALYSIS  THREAT ANALYSIS  VULNERABILITY ANALYSIS  RISK IDENTIFICATION  RISK ANALYSIS  RISK TREATMENT  MONITORING RISK
  • 8.
    INTEGRATION WITH OTHER MANAGEMENTPRACTICES  Budgeting  Business Planning  Internal Audit  Periodic Reporting