官术网_书友最值得收藏!

What is risk management?

Risk management and risk ownership are two very different things. While risk ownership is an executive/board responsibility, risk management is a delegated responsibility that extends throughout the organization:

  • While risk ownership sits with the most senior leaders of an organization, risk management is a team sport.
  • Risk management spans from the most junior front-line employee up to senior management.
  • Risk management duties are delegated down from the senior management.
  • Risk acceptance cannot be delegated. Risk acceptance decisions must be made by the risk owners and must be communicated effectively by the risk managers.

It is a very common trap for an IT professional to fall into to think that they are the risk owner because they are responsible for an information system. The IT professional may be inclined to make decisions that relate to the risk of an IT system that they are not authorized to make, which can lead to an inadvertent exposure for the organization. Risk should be communicated up the organizational hierarchy to the risk owners via a repeatable risk management process.

主站蜘蛛池模板: 宜君县| 柞水县| 团风县| 阿克陶县| 曲沃县| 彩票| 定边县| 渭南市| 什邡市| 仙游县| 垦利县| 高平市| 金堂县| 合江县| 神农架林区| 襄城县| 潍坊市| 美姑县| 蓬溪县| 高淳县| 徐州市| 曲阳县| 麦盖提县| 汉寿县| 武平县| 邵东县| 精河县| 长宁县| 获嘉县| 固安县| 汤阴县| 绥中县| 兰溪市| 广宁县| 井陉县| 黄冈市| 麟游县| 大厂| 阿城市| 康马县| 土默特右旗|