IT-412 Cyberlaw and Ethics
Short Paper 5-1
Risk Assessment and Response Plans
Jason Popejoy
Southern New Hampshire University
The risk assessment process allows businesses to identify and prepare for potential risks
Allowing them to avoid catastrophic consequences and keep employees safe in the future
During the risk assessment process, businesses look to identify hazardous processes and
situations that may cause harm to people or company data. Second, it is decided who might be
harmed by these risks and how. Then, the risks are evaluated, and precautionary steps are
decided. Findings are then recorded, and the assessment is reviewed and updated if necessary
The top-down approach begins with a company's upper management. These managers
are responsible for creating, initiating, and implementing data protection strategies. These
strategies may include policy creation, procedural instructions and plans for escalation (Box
Communications, 2021). Top-level managers may also seek out assistance in the form of training
or a partnership with an infosec service, and company resources (Box Communications, 2021).
The top-down approach looks at the data from each department looking at how each department
is interconnected to find vulnerabilities. Managers have the ability to issue instructions to all
employees and still allow each employee to help keep data safe. In this way, a top-down
approach makes data security a company-wide priority (Box Communications, 2021).
If IT tries to implement an assessment or plan for the entire organization, the senior
management may have other plans or additional ideas to be implemented. If a plan developed by
the IT department that is not supported by senior management, the plan is most likely to fail.
This may be because senior management does not believe the plan is as good as the plan they
have developed. In these situations, senior management and the IT department need to have their
own meeting and agree on risk assessments for benefit of the entire company. Doing this will aid
the company run smoother, with less possibility of an event being mishandled.
References
Lucid Content Team. (2018, June 11). A complete guide to the risk assessment process. A
Complete Guide to the Risk Assessment Process | Lucidchart Blog. Retrieved from
https://www.lucidchart.com/blog/risk-assessment-process
Guide for Conducting Risk Assessments. (n.d.). Retrieved February 10, 2018, from
http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf
Managing Information Security Risk . (n.d.). Retrieved February 10, 2018, from
http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-39.pdf
Box Communications. (2021, April 20). Approaches to information security implementation
Box Blog. Retrieved from https://blog.box.com/approaches-information-security-
implementation