Risk Frameworks

Similar to (and, in some cases, overlapping with) the security control frameworks, the security professional may also make use of risk frameworks to optimize the organization's response to risk. In many mature organizations, this effort defines the organization's strategy in terms of Business risks and opportunities and is often referred to as enterprise risk management (ERM). Many different standards bodies and industry-specific entities publish ERM guidance and documentation. These include (but are not limited to):

4 slides · 2 min read · Domain 1

Slide 1

ISACA

Publishes the RISK IT framework, which is described by ISACA as connecting risk management from a strategic perspective with risk-related IT management. The framework was published in 2009 by ISACA after creating a joint workgroup with industry leaders such as Ernst & Young,IBM,PricewaterhouseCoopers, KPMG and others. The framework explains IT risk

and enables users to:

  • Integrate IT risk management with the overall ERM approach.
  • Compare assessed IT risk with the organizations' risk tolerance and appetite.
  • Understand how to manage IT risks.
  • Connect risk management from a strategic perspective with risk-related IT management.

Committee Of Sponsoring Organizations (COSO)

Committee of Sponsoring Organizations (COSO) of the Treadway Commission was formed in the wake of dramatic and severe financial industry scandals in the United States in the 1980s, as a body to suggest guidelines and practices to address financial reporting irregularities and fraud. Since that time, its publications have been widely accepted and adopted by many large companies. In 2004, COSO published the first version of its Enterprise Risk Management - Integrated Framework; this document was updated in 2017 and is seen as a definitive guide to the topic.

ISO:Standards 31000 and 27005

ISO:Standards 31000 (Risk Management

  • Principles and Guidelines) and 27005 (Information technology - Security techniques - Information security risk management) both discuss risk from a holistic organizational perspective (the former) and as specifically related to IT security (the latter). Standard 27001 is also endorsed by ENISA (the European Union Agency for Network and Information Security) as a means of managing risk.

Nist Special Publication (SP) 800-37

NIST Special Publication (SP) 800-37 is the Risk Management Framework (RMF), which is extremely influential and important for how U.S. federal government agencies address risk but was also adopted by private sector organizations. It has also had substantial influence globally, both in the public and private sectors.

Test this domain