Context of Information Security
Risk management in the context of information security refers to policies and procedures used to thwart the risks of a breach, hack or other cyber attack. These risks can be damaging to a company’s reputation, financials or operational efficiency.
There are many ways to reduce a business’s risk, including deploying risk assessment tools and processes, implementing mitigation strategies and establishing an incident response plan. Risk management is an ongoing process, and as technology evolves so must the strategy used to address it.
The first step of risk management is identifying potential threats that could harm a business’s data, infrastructure or reputation. This can be accomplished by conducting a risk assessment, which will examine the likelihood of a threat and its impact on an organization. Once risks have been identified, they can be prioritized and treated accordingly.
A threat can be anything from a stakeholder withdrawing support during a project to lightning striking an airplane just before takeoff, and it is important to consider all possible sources of a problem (note: we use the word “source” instead of “problem” since risk management deals with factors that can influence decision-making but are not directly under a control’s purview, such as the weather over an airport). Once a potential source has been identified, it must be evaluated to determine the impact it could have on the business and whether a solution exists.

Risk Management in the Context of Information Security
For example, if employees write their workplace login credentials on a post-it note and the note is found by someone who can use it to impersonate an employee, this would pose a risk to confidential information. However, if employees are instructed to use secure systems rather than personal email accounts to communicate with each other, this will protect the organization’s PHI from unauthorized disclosure.
Once a potential risk has been identified, it can be prioritized and treated accordingly. This can be done by assessing its impact and probability of occurring, as well as comparing it to the costs associated with implementing a mitigation strategy. For instance, the cost of a data breach could be compared to the cost of redeploying servers that were originally installed on obsolete operating systems that no longer receive security updates.
A risk treatment plan is then created for each of the prioritized risks. This includes purchasing insurance policies for those risks that are deemed too costly to mitigate, avoiding those risks that can be avoided without sacrificing the organization’s goals, reducing others and accepting the remaining ones. The risk owner is responsible for implementing the different treatment plans, which may involve involving the risk management team, the information security team, the system owners and/or the system administrators.
While there are several approaches to risk management, the most effective one is to build a culture of risk awareness and encourage employees at all levels to act as one team against all forms of threat. This requires leadership buy-in to ensure that everyone is on the same page when it comes to protecting the company’s reputation, finances, data and operations.
