Information security risk management: from assets to management decisions

Regulation & securityBy: Parsa Aghabarari2 min readSource: ISC2
Information security risk management: from assets to management decisions

1Introduction

Risk management systematically identifies, analyses, evaluates and treats information risks; it is CISSP’s first domain and the core of ISO 27001.

2Discussion

Start with assets, then threats and vulnerabilities.

Estimate likelihood and impact, qualitatively or quantitatively, to prioritise.

Treat by mitigating, transferring, avoiding or accepting; business owners decide on residual risk.

3Conclusion

Repeat periodically and report to leadership.

Share:TelegramWhatsAppLinkedIn

Sources

  1. ISC2 ↗
  2. NIST ↗
همفکران فناوری شریفThis article summarises the official sources cited, prepared by the Hamfekran Fanavari Sharif team for finance leaders.
Want to see these solutions in your organisation?Book a free demo

Related articles

Regulation & securityDigital customer onboarding (eKYC): opening accounts without visiting a branchRemote identity verification is the gateway to digital banking; the challenge is balancing convenience with fraud resistance.Regulation & securityPCI DSS v4: card data security in the digital payments eraAny organisation storing, processing or transmitting card data faces PCI DSS; v4 introduces a more flexible, risk-based approach.Regulation & securityRespected cybersecurity certifications: from CISSP to OSCPProfessional certifications are the global job market’s common language; knowing each one’s role helps choose well.Regulation & securityCyber attacks on banks: from messaging-network heists to stealthy intrusionsBanks are prime targets for organised attackers; known incidents reveal recurring patterns and lessons.