• Home
  • Southern New Hampshire University
  • Cyberlaw and Ethics IT412
  • Cyberlaw and Ethics Risk Assessment

Cyberlaw and Ethics Risk Assessment

Running Head: 5-1 SHORT PAPER IT-412: Cyberlaw and Ethics 5-1 Short Paper: Risk Assessment and Response Plans Christopher Gouchenouer Alicia L. Peltier Southern New Hampshire University 8/4/2019 SHORT PAPER According to the National Institute of Standards and Technology (NIST) (2012), "Risk assessments are used to identify, estimate and prioritize risk to organizational operations (i.e mission, functions, images and reputation), organizational assets, individuals, other organizations and the nation, resulting from the operation and use of information systems" (Guide for Conducting Risk Assessments, p. 4). Risk assessment framework is used in the evaluation of all potential risks that an organization could come across at any time. The organization can then utilize the process for evaluating the risk that has been identified and devise a plan accordingly The process for properly assessing a risk is divided into four components of risk management that are described in NIST's Guide for Conducting Risk Assessments which are listed below: 1. Frame the risk by establishing the context for risk-based decisions 2.Assess the risk 3. Respond to the risk once it is determined 4. Monitor the risk by communicating with the organizational teams while utilizing any feedback from the team to implement a plan for continuous improvement in the risk related activities of the organization SHORT PAPER Risk management is used as an organizational activity which addresses risks at all levels of an organization to ensure that proper risk-based decisions are being made relating to all aspects of the business (Guide for Conducting Risk Assessments, p.6). When looking at the second component, Assessing the Risk, it is broken down into four stages for assessing a risk. They are: 1. Identify the threat directed against the organization 2. Identify any internal/external vulnerabilities to the organization 3. Assess the consequences and/or impact to the organization 4. Assess the probability that harm will occur to the organization Once there has been a risk assessment performed, the organization must design a proper response plan for dealing with the risk that has been identified. The type of risk that the organization is facing will determine how they will respond in combatting the risk. A risk can be accepted if it is able to be tolerated, absorbed, avoided, mitigated or shared/transferred (Managing Information Security Risk, 2011). There are two common approaches for dealing with risk management. They are the top down approach and the bottom up approach. The bottom up approach takes the stance that an organization has to identify risks in a specific order as follows: Process level, project/departmental level, vertical/functional level, business unit level and lastly, the organizational level. The bottom-up approach has the ability to use all resources that are available as well as consuming all available time allotted yet it would give an accurate description of the risk. On the other side of the spectrum, the top-down approach may lead to sub-par solutions due to a lack of data available that will identify how the organization may be affected by the risk and how they should proceed in mitigati