Risk management is a key element in information security management, where the goal is to reduce the likelihood of adverse impacts resulting from cyber incidents. Cybersecurity risk management is the process of identifying, assessing, prioritizing, and mitigating risks resulting from exposure to cyber threats that can compromise an organization’s information assets. It involves a systematic approach to identifying and understanding threats, vulnerabilities and risks, followed by managing the risks by reducing their likelihood and impact. In addition, all this needs to be done in a cost-effective way, meaning that the cost of reducing a risk should never be greater than the value of the risk reduction it achieves. Hence, cyber risk management requires both technical and business skills to be well aligned with business objectives.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Cyber Risk Management

  • Audun Jøsang

摘要

Risk management is a key element in information security management, where the goal is to reduce the likelihood of adverse impacts resulting from cyber incidents. Cybersecurity risk management is the process of identifying, assessing, prioritizing, and mitigating risks resulting from exposure to cyber threats that can compromise an organization’s information assets. It involves a systematic approach to identifying and understanding threats, vulnerabilities and risks, followed by managing the risks by reducing their likelihood and impact. In addition, all this needs to be done in a cost-effective way, meaning that the cost of reducing a risk should never be greater than the value of the risk reduction it achieves. Hence, cyber risk management requires both technical and business skills to be well aligned with business objectives.