官术网_书友最值得收藏!

Risk ownership

Understanding risk ownership, and who does not own risk, is critically important in order to make the correct risk decisions that support your organization's business and mission objectives:

  • Risk ownership is held by the C-suite and/or people at the boardroom level.
  • The ability to own risk is tied to authority and the ability to commit funds to reduce risk.
  • Senior leaders have the ability to fund risk reduction efforts as well as the ability to change the direction of organizational efforts and culture.
  • It is critically important that risks to the organization be effectively communicated to senior leadership with effective, well thought out plans to reduce risk.
  • While risk ownership sits with the executive team of an organization, it is the responsibility of the information security professional to deliver the facts regarding organizational risk coupled with the necessary plans of action to reduce the risk to acceptable levels.
  • This is where an effective understanding of the organization comes into play. Senior leadership will not be receptive to your risk reduction strategies if they do not align with the organizational mission.
主站蜘蛛池模板: 炉霍县| 烟台市| 珲春市| 大冶市| 平度市| 亳州市| 南和县| 云林县| 光山县| 庆安县| 白山市| 佛坪县| 巢湖市| 乐都县| 宁国市| 双桥区| 呼图壁县| 枝江市| 博野县| 余姚市| 达孜县| 宝清县| 许昌市| 抚顺市| 太康县| 嘉鱼县| 清镇市| 容城县| 景东| 南漳县| 萍乡市| 莱阳市| 静安区| 巴彦淖尔市| 胶南市| 稷山县| 太仆寺旗| 吉林省| 微山县| 巢湖市| 高尔夫|