• Home
  • Southern New Hampshire University
  • Cyberlaw and Ethics IT412
  • Risk Assessment and Response Plans in Cyberlaw and Ethics

Risk Assessment and Response Plans in Cyberlaw and Ethics

IT-412 Cyberlaw and Ethics Short Paper 5-1 Risk Assessment and Response Plans Jason Popejoy Southern New Hampshire University The risk assessment process allows businesses to identify and prepare for potential risks Allowing them to avoid catastrophic consequences and keep employees safe in the future During the risk assessment process, businesses look to identify hazardous processes and situations that may cause harm to people or company data. Second, it is decided who might be harmed by these risks and how. Then, the risks are evaluated, and precautionary steps are decided. Findings are then recorded, and the assessment is reviewed and updated if necessary The top-down approach begins with a company's upper management. These managers are responsible for creating, initiating, and implementing data protection strategies. These strategies may include policy creation, procedural instructions and plans for escalation (Box Communications, 2021). Top-level managers may also seek out assistance in the form of training or a partnership with an infosec service, and company resources (Box Communications, 2021). The top-down approach looks at the data from each department looking at how each department is interconnected to find vulnerabilities. Managers have the ability to issue instructions to all employees and still allow each employee to help keep data safe. In this way, a top-down approach makes data security a company-wide priority (Box Communications, 2021). If IT tries to implement an assessment or plan for the entire organization, the senior management may have other plans or additional ideas to be implemented. If a plan developed by the IT department that is not supported by senior management, the plan is most likely to fail. This may be because senior management does not believe the plan is as good as the plan they have developed. In these situations, senior management and the IT department need to have their own meeting and agree on risk assessments for benefit of the entire company. Doing this will aid the company run smoother, with less possibility of an event being mishandled. References Lucid Content Team. (2018, June 11). A complete guide to the risk assessment process. A Complete Guide to the Risk Assessment Process | Lucidchart Blog. Retrieved from https://www.lucidchart.com/blog/risk-assessment-process Guide for Conducting Risk Assessments. (n.d.). Retrieved February 10, 2018, from http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf Managing Information Security Risk . (n.d.). Retrieved February 10, 2018, from http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-39.pdf Box Communications. (2021, April 20). Approaches to information security implementation Box Blog. Retrieved from https://blog.box.com/approaches-information-security- implementation