Risk Assessment and Incident Response
It is clear why a company should invest the resources to establish an incident response program: consider the results and impact on a corporation that suffers a disaster without having prepared for it! In other words, what level of risk is a company willing to accept on its information resources and businesses?
This is addressed through the concept of risk management, or when senior management conducts a cost-benefit analysis to weigh the pros and cons of implementing various security countermeasures such as an incident response program. Risk management defines levels of risk by examining the types and probabilities of threats and vulnerabilities associated with a given organization and balances those findings against the costs associated with protecting against such potential problems. These assessments help senior management decide the level of risk they and the company are willing to accept as a result of implementing (or not implementing) specific countermeasures to potential security problems. For example, not having an incident response process may mean extended periods of downtime and confusion that could affect business operations or revenue, just as not having a properly configured firewall increases the probability of a network being compromised.
While many resources ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access