It is an accepted truth that without risk there can be no gain.  Every individual and organization must take some risks to succeed. Risk management is not about avoiding risks, but about taking risks in a  controlled environment. To do this, one must understand the risks, the triggers, and the consequences.

Instructions

Write a 3–4 page paper in which you:

  1. Define risk management and information security clearly.  Discuss how information security differs from information risk management.
  2. Explain security policies and how they factor into risk management.
  3. Describe at least two responsibilities for both IT and non-IT leaders in information risk management.
  4. Describe how a risk management plan can be tailored to produce information and system-specific plans.
  5. Use at least two quality resources in this assignment. Note:  Wikipedia and similar Websites do not qualify as quality resources. The  Strayer University Library is a good source of resources..

The specific course learning outcome associated with this assignment is:

  • Assess how risk is addressed through system security policies, system-specific plans, and contingency plans