Risk Frameworks
Similar to (and, in some cases, overlapping with) the security control frameworks, the security professional may also make use of risk frameworks to optimize the organization's response to risk. In many mature organizations, this effort defines the organization's strategy in terms of Business risks and opportunities and is often referred to as enterprise risk management (ERM). Many different standards bodies and industry-specific entities publish ERM guidance and documentation. These include (but are not limited to):
4 slides · 2 min read · Domain 1
ISACA
Publishes the RISK IT framework, which is described by ISACA as connecting risk management from a strategic perspective with risk-related IT management. The framework was published in 2009 by ISACA after creating a joint workgroup with industry leaders such as Ernst & Young,IBM,PricewaterhouseCoopers, KPMG and others. The framework explains IT risk
and enables users to:
- Integrate IT risk management with the overall ERM approach.
- Compare assessed IT risk with the organizations' risk tolerance and appetite.
- Understand how to manage IT risks.
- Connect risk management from a strategic perspective with risk-related IT management.
Committee Of Sponsoring Organizations (COSO)
Committee of Sponsoring Organizations (COSO) of the Treadway Commission was formed in the wake of dramatic and severe financial industry scandals in the United States in the 1980s, as a body to suggest guidelines and practices to address financial reporting irregularities and fraud. Since that time, its publications have been widely accepted and adopted by many large companies. In 2004, COSO published the first version of its Enterprise Risk Management - Integrated Framework; this document was updated in 2017 and is seen as a definitive guide to the topic.
ISO:Standards 31000 and 27005
ISO:Standards 31000 (Risk Management
- Principles and Guidelines) and 27005 (Information technology - Security techniques - Information security risk management) both discuss risk from a holistic organizational perspective (the former) and as specifically related to IT security (the latter). Standard 27001 is also endorsed by ENISA (the European Union Agency for Network and Information Security) as a means of managing risk.
Nist Special Publication (SP) 800-37
NIST Special Publication (SP) 800-37 is the Risk Management Framework (RMF), which is extremely influential and important for how U.S. federal government agencies address risk but was also adopted by private sector organizations. It has also had substantial influence globally, both in the public and private sectors.
