ISO 27001 | SSAE 18 SOC 2 Certified Sales: 317.275.0021 NOC: 317.275.0001
ComputerWeekly: Refining the language of risk
When it comes to risk analysis, one of the most important tools an IT executive can deploy is compelling language.
Getting buy-in from senior management is one of the most, if not the most, important prerequisite for effective IT risk management. Senior management will not be interested in the gritty technical details; they will want to ensure that risk analysis:
Contains thoughtful consideration of all possible risk events
Uses domain expertise and whatever useful security metrics exist to determine event probabilities
Leverages business owners’ knowledge of their operations to consider the impact of various risk events to the business in a meaningful way
Introduces as much objectivity and precision as possible into the risk analysis process
Produces prioritized output to guide executive decision-making on risk management
Is communicated, including its findings and recommendations, in clear and understandable language
More of the ComputerWeekly article from Jim Hietala