官术网_书友最值得收藏!

Risk ownership

Understanding risk ownership, and who does not own risk, is critically important in order to make the correct risk decisions that support your organization's business and mission objectives:

  • Risk ownership is held by the C-suite and/or people at the boardroom level.
  • The ability to own risk is tied to authority and the ability to commit funds to reduce risk.
  • Senior leaders have the ability to fund risk reduction efforts as well as the ability to change the direction of organizational efforts and culture.
  • It is critically important that risks to the organization be effectively communicated to senior leadership with effective, well thought out plans to reduce risk.
  • While risk ownership sits with the executive team of an organization, it is the responsibility of the information security professional to deliver the facts regarding organizational risk coupled with the necessary plans of action to reduce the risk to acceptable levels.
  • This is where an effective understanding of the organization comes into play. Senior leadership will not be receptive to your risk reduction strategies if they do not align with the organizational mission.
主站蜘蛛池模板: 满洲里市| 三台县| 云南省| 三河市| 横峰县| 昭平县| 红桥区| 洪泽县| 遂川县| 滨州市| 富顺县| 泰安市| 缙云县| 馆陶县| 景谷| 玛纳斯县| 镇原县| 彰化市| 福安市| 磐石市| 微博| 巩留县| 平南县| 巨鹿县| 清流县| 洛浦县| 宁蒗| 陇西县| 临猗县| 昌黎县| 上犹县| 彭山县| 舟曲县| 新源县| 漾濞| 仙游县| 沾化县| 宜宾县| 余庆县| 伊宁市| 唐海县|