CHAPTER 4Information Asset Risk Planning and Management
Information asset risk planning is a key information governance (IG) program activity. In fact, much of IG is about managing information risk, and often, information risk analysis is a regulatory obligation.1 Many times organizations have identified risks to information, but have not taken the appropriate risk assessment and mitigation steps to counter those risks.
There are various types of risks to information assets, including the risk of noncompliance with legal regulations; technology risks centered around cybersecurity and system maintenance; external and internal data breaches; management risks related to managing change, system planning, and providing proper training; and even natural disasters or rare disasters caused by humans, such as the 9/11 attacks in New York City.
Information asset risk planning requires that the organization take a number of specific steps in identifying, analyzing, and countering information risks:
- Identify risks. Conduct a formal process of identifying potential vulnerabilities and threats (both external and internal) to information assets.
- Assess impact. Determine the potential financial and operational impact of the identified adverse events.
- Determine probability. Weigh the likelihood that the identified risk events materialize.
- Countermeasures. Create high-level strategic plans to mitigate the greatest risks.
- Create policy. Develop strategic plans into specific policies.
- Establish ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access