Running Head: 5-1 SHORT PAPER
IT-412: Cyberlaw and Ethics 5-1 Short Paper: Risk Assessment and Response Plans
Christopher Gouchenouer
Alicia L. Peltier
Southern New Hampshire University
8/4/2019
SHORT PAPER
According to the National Institute of Standards and Technology (NIST) (2012), "Risk
assessments are used to identify, estimate and prioritize risk to organizational operations (i.e
mission, functions, images and reputation), organizational assets, individuals, other organizations
and the nation, resulting from the operation and use of information systems" (Guide for
Conducting Risk Assessments, p. 4). Risk assessment framework is used in the evaluation of all
potential risks that an organization could come across at any time. The organization can then
utilize the process for evaluating the risk that has been identified and devise a plan accordingly
The process for properly assessing a risk is divided into four components of risk management
that are described in NIST's Guide for Conducting Risk Assessments which are listed below:
1. Frame the risk by establishing the context for risk-based decisions
2.Assess the risk
3. Respond to the risk once it is determined
4. Monitor the risk by communicating with the organizational teams while utilizing
any feedback from the team to implement a plan for continuous improvement in
the risk related activities of the organization
SHORT PAPER
Risk management is used as an organizational activity which addresses risks at all levels
of an organization to ensure that proper risk-based decisions are being made relating to all
aspects of the business (Guide for Conducting Risk Assessments, p.6).
When looking at the second component, Assessing the Risk, it is broken down into four
stages for assessing a risk. They are:
1. Identify the threat directed against the organization
2. Identify any internal/external vulnerabilities to the organization
3. Assess the consequences and/or impact to the organization
4. Assess the probability that harm will occur to the organization
Once there has been a risk assessment performed, the organization must design a proper
response plan for dealing with the risk that has been identified. The type of risk that the
organization is facing will determine how they will respond in combatting the risk. A risk can be
accepted if it is able to be tolerated, absorbed, avoided, mitigated or shared/transferred
(Managing Information Security Risk, 2011).
There are two common approaches for dealing with risk management. They are the top
down approach and the bottom up approach. The bottom up approach takes the stance that an
organization has to identify risks in a specific order as follows: Process level,
project/departmental level, vertical/functional level, business unit level and lastly, the
organizational level. The bottom-up approach has the ability to use all resources that are
available as well as consuming all available time allotted yet it would give an accurate
description of the risk. On the other side of the spectrum, the top-down approach may lead to
sub-par solutions due to a lack of data available that will identify how the organization may be
affected by the risk and how they should proceed in mitigati