官术网_书友最值得收藏!

What is risk management?

Risk management and risk ownership are two very different things. While risk ownership is an executive/board responsibility, risk management is a delegated responsibility that extends throughout the organization:

  • While risk ownership sits with the most senior leaders of an organization, risk management is a team sport.
  • Risk management spans from the most junior front-line employee up to senior management.
  • Risk management duties are delegated down from the senior management.
  • Risk acceptance cannot be delegated. Risk acceptance decisions must be made by the risk owners and must be communicated effectively by the risk managers.

It is a very common trap for an IT professional to fall into to think that they are the risk owner because they are responsible for an information system. The IT professional may be inclined to make decisions that relate to the risk of an IT system that they are not authorized to make, which can lead to an inadvertent exposure for the organization. Risk should be communicated up the organizational hierarchy to the risk owners via a repeatable risk management process.

主站蜘蛛池模板: 惠安县| 苏尼特右旗| 郸城县| 昌黎县| 抚松县| 清丰县| 利津县| 康保县| 微博| 太白县| 蓬溪县| 临高县| 汝州市| 香河县| 潢川县| 沾化县| 五莲县| 伊春市| 凌源市| 都江堰市| 罗源县| 平安县| 兴山县| 拉孜县| 鲁山县| 永寿县| 伊春市| 安多县| 北京市| 万州区| 深水埗区| 新和县| 江都市| 南丹县| 安塞县| 桓仁| 松阳县| 屏山县| 湟中县| 宕昌县| 景谷|