Risk management: which is the process to identify control and minimize the impact of threats
Risk: the probability or likelihood that the thread will impact information resources.
We cannot fully control threats instead we have to attempt to minimize or mitigate them hence the need of risk management,
risk management: finding ways to minimize the likelihood of a certain outcome from occurring and achieving the outcomes we want to
1.performing risk analysis: to identify the risks in place then moves on
2.mitigation activities: that reduce the likelihood that those risks will occur and the impact on the organization if they do occur such mitigation
activities include implementations of control to prevent threats from occurring and development of recovery plans to cater for situations where
the threats becomes reality up to this point.
Strategies to deal risk:
1.risk transference: is a risk mitigation strategy that passes the risk to a third party most commonly an insurance company a
good example of this would be if your organization was worried about the risk of your server room being destroyed by the natural
disaster if you are concerned about this you could purchase the natural disaster insurance policy to transfer the risk of losing all
those assets to the insurance company.
2. Risk limitations which is a strategy that seeks to minimize the risks to an acceptable level where the organization can then
accept the remaining risk for example if you have a server that has been identified to have five critical two high four medium and
let’s say 17 low vulnerabilities your organization’s risk management program may have a policy that states that any server with
critical vulnerabilities should be taken offline to minimize the risk you can patch those five critical vulnerabilities now since the
overall risk was mitigate down.
3.Risk acceptance seeks to accept the current level of risk and the cost associated with it generally this would be the proper