Preview

ISSC363 Assignment 3

Satisfactory Essays
Open Document
Open Document
586 Words
Grammar
Grammar
Plagiarism
Plagiarism
Writing
Writing
Score
Score
ISSC363 Assignment 3
Conducting a thorough risk assessment is certainly one of the top priorities in the overall risk management program. It is a process of identifying and evaluating the risks that can have a negative impact on an organization. Once the risks have been successfully captured, they can be assessed and prioritized according to the severity of their potential impact. While every organization should have a continuous risk management program, a risk assessment is conducted at a given moment in time, and as such should be repeated on some predetermined schedule to reevaluate the risks and adjust as appropriate. To conduct an effective risk assessment, it’s important to be able to fundamentally describe of the purpose of a risk assessment, risk scope and identify critical areas for an assessment. Additionally, a methodology that is appropriate for the risk assessment should be selected.
At its core, the purpose of a risk assessment is identifying and evaluating risks that may potentially have a negative impact on an organization. It can help management understand the impact in terms of costs to the organization or the severity of a loss depending on the methodology used to conduct the risk assessment. The goal is to provide sound recommendations based on the risk assessment to help maintain data confidentiality, integrity and vulnerability while ensuring functionality and usability. Based on the results, management can make more informed decisions about what resources to protect, how to protect them and understand the potential costs and impact. Once the purpose of the risk assessment is understood, defining the scope is next.
The scope of a risk assessment is possibly one of the most important steps to be conducted. The scope defines the limitations and sets the parameters of the risk assessment to ensure it stays within costs and the desired timeframe. The scope identifies the required resources, systems/applications to be assessed and protected, and the level



References: Bayne, J. (2002). An overview of threat and risk assessment. SANS Institute. Retrieved from http://www.sans.org/reading-room/whitepapers/auditing/overview-threat-risk-assessment-76 Gibson, D. (2010). Managing Risk in Information Systems. Sudbury, MA. Jones & Bartlett Learning. Retrieved from http://ebooks.apus.edu.ezproxy2.apus.edu/ISSC363/Gibson_2011_Ch5.pdf

You May Also Find These Documents Helpful

  • Better Essays

    risk assessments - process of evaluating the potential risks that may be involved in method of work…

    • 1528 Words
    • 7 Pages
    Better Essays
  • Powerful Essays

    This is a statement to say that every member of this group contributed their equitable share to the Group Assignment, with regard to presentations, writing and group meetings.…

    • 13536 Words
    • 144 Pages
    Powerful Essays
  • Powerful Essays

    nt2580 lab 6

    • 1092 Words
    • 5 Pages

    A risk analysis (RA) focuses on all aspects of risk assessment for an organization and is a necessary step…

    • 1092 Words
    • 5 Pages
    Powerful Essays
  • Good Essays

    Unit 6 Assignment 2

    • 878 Words
    • 4 Pages

    The problem of risk assessment is an extremely complex one. When a risk assessment process is started, this process has to analyze several aspects in parallel.…

    • 878 Words
    • 4 Pages
    Good Essays
  • Powerful Essays

    Risk assessment is determining two quantities of the risk, the magnitude of the potential loss and the probability that the loss will occur. Risk assessment then is a step in the risk management process, http://en.wikipedia.org/wiki/Risk_Assessment. An organization has to have policies in place to identify and manage risks. Oldfield and Santomero (n.d.) developed the following guidelines to successfully implement the risk management policy set up by the business:…

    • 1974 Words
    • 8 Pages
    Powerful Essays
  • Good Essays

    The following paper discusses the risk assessment process while explaining the framework, how each phase interrelates, and why the framework is so important in assisting with the risk assessment process. The paper will also discuss some of the innovations that have occurred over the last several years.…

    • 823 Words
    • 4 Pages
    Good Essays
  • Good Essays

    IS 3110 lab 4 questions

    • 403 Words
    • 2 Pages

    The aim of the risk assessment process is to remove a hazard or reduce the level of its risk by adding precautions or control measures, as necessary. By doing so, you have created a safer and healthier workplace.…

    • 403 Words
    • 2 Pages
    Good Essays
  • Better Essays

    Before developing a risk management plan an analysis of risk needs to be performed. This analysis should include all aspects of the project that may be part of an uncertain event or condition that may have a positive or negative effect on the project objectives and outcome. The overall goal is to work to address any type of risk before they become problematic. Analyzing and relaying the level and probability of the risk to the stakeholders, sponsors and project team can help in reducing mistakes that can be cause for project failures. Some common mistakes that can be overlooked when analyzing risk, is not understanding the benefits of a risk management plan, not allowing time for risk management, not properly identifying and assessing risk.…

    • 1195 Words
    • 5 Pages
    Better Essays
  • Satisfactory Essays

    4223-007

    • 344 Words
    • 2 Pages

    The important issues are whether a known or potential risk is likely to occur, if it will be significant should it occur, and whether the organization is adequately prepared to handle it so that the negative effects are eliminated or minimized.…

    • 344 Words
    • 2 Pages
    Satisfactory Essays
  • Good Essays

    Risk Assessment

    • 768 Words
    • 3 Pages

    Before proceeding with the expansion project, management has asked you to lead a team that will estimate the risks associated with this project. They want you to provide a high level summary of quantitative and qualitative risks associated with the following items:…

    • 768 Words
    • 3 Pages
    Good Essays
  • Satisfactory Essays

    The purpose of a risk assessment is to review the potential harm that could be caused and evaluate the likelihood of harm occurring.…

    • 510 Words
    • 3 Pages
    Satisfactory Essays
  • Satisfactory Essays

    Jemma Taqa

    • 444 Words
    • 3 Pages

    3.4 Summarise the types of risks that may be involved in assessment in own area of responsibility…

    • 444 Words
    • 3 Pages
    Satisfactory Essays
  • Powerful Essays

    A risk assessment is an important step in which protects a business, employers and employees, as well as complying with the law. This helps to focus on the risks that have the potential to cause harm in a workplace. When thinking of ways how to control risks it can be a straightforward and simple process, for an example ensuring spillages are cleaned up quickly and effectively, so people do not slip. Risk assessments are simply a careful examination of what, in a work setting could cause harm to people. In order to weigh up whether you have taken enough precautions or should do more to prevent harm.…

    • 3026 Words
    • 13 Pages
    Powerful Essays
  • Satisfactory Essays

    Note that cybersecurity is a risk management issue; therefore, the project risks are identified to reveal the events that may negatively impact the project’s objectives or results. Essentially, a risk assessment is a process of evaluating the project risks; hence, the risk assessment provides details on the risk factors associated with implementing the project as well as how to mitigate those risks. Following is a risk analysis and cost-benefit analysis of the project moving forward.…

    • 77 Words
    • 1 Page
    Satisfactory Essays
  • Powerful Essays

    Risk Assessment

    • 1788 Words
    • 8 Pages

    Almost every company in business is face with some risk or potential threat that could cause a huge blow to their organization operations. These risks and threats usually comes from within or outside and organization. In order to prepare for the worst that could happen, organizations must focus their attention on how to assess different types of risk so they could protect themselves from the harm caused by them. Risks involve theoretical effectiveness of security measures, loss of impact, threats and vulnerabilities that are common in today's society.…

    • 1788 Words
    • 8 Pages
    Powerful Essays