Determining Your Risk Tolerance

What is your organization’s risk tolerance?

The process of determining risk tolerance can be a tricky one. However, there are specific steps that can be taken to determine risk tolerance and help secure your organization.

It’s not a case of one-size-fits-all; each organization needs a customized system. As Craig Shumard points out in this article, different organizations are motivated by different factors. For this reason, it is important that organizations establish a formal risk assumption model involving the CEO or Board of Directors.

After the risk has been identified, the next step is to determine who is authorized to make security risk decisions. In most cases, the best option is to have the CISO serve as the first line of defense. This means making sure that the CISO has the appropriate clearance and authority over security matters.

Original article by Craig Shumard.
Read the full story here.

Related Posts

Considerations – Why you should choose infotex, Inc. as your next MSOC!

Reasons why we should be considered! infotex provides a number of services that can be checked out if you click over to! We even made a movie with all the reasons why infotex...

The Magnificent Seven 2023

Seven Trends . . . …that small bank Information Security Officers face in 2023 Another one of those Dan’s New Leaf Posts, meant to inspire thought about IT Governance . . . . Welcom...