SECURING THE ENTERPRISE
Friday, October 08, 2010
The objective of performing risk management is to enable the organization to accomplish its mission by better securing the IT systems that store, process, or transmit organizational information and by enabling management to make well-informed risk management decisions to justify the expenditures that are part of an IT budget and by assisting management in authorizing on the basis of the supporting documentation resulting from the performance of risk management .An effective risk management process is an important component of a successful IT security program. The principal goal of an organization’s risk management process should be to protect the organization and its ability to perform their mission and its IT assets.
Information security requires far more than the latest tool or technology. Organizations must understand exactly what they are trying to protect--and why--before selecting specific solutions. Security issues are complex and often are rooted in organizational and business concerns. A careful evaluation of security needs and risks in this organization will develop and maintain a program to adequately secure its information and systems assets. Risk management encompasses three processes: risk assessment, risk mitigation, and evaluation and assessment. A security plan implementation will help to insure that all the relevant, underlying problems are first uncovered.
A flexible evaluation process can adapt to changing technology and advancements. It is not constrained by a rigid model of current sources of threats or by what practices are currently accepted as “best.” Because the information security and information technology domains change very rapidly, an adaptable set of measures against which an organization and its unique context can be evaluated is essential. Adaptable measures require:
• Current catalogs of... [continues]
Cite This Essay
(2011, 04). Case Study of Securing Enterprise. StudyMode.com. Retrieved 04, 2011, from http://www.studymode.com/essays/Case-Study-Of-Securing-Enterprise-661377.html
"Case Study of Securing Enterprise" StudyMode.com. 04 2011. 04 2011 <http://www.studymode.com/essays/Case-Study-Of-Securing-Enterprise-661377.html>.
"Case Study of Securing Enterprise." StudyMode.com. 04, 2011. Accessed 04, 2011. http://www.studymode.com/essays/Case-Study-Of-Securing-Enterprise-661377.html.