Strategic Information Security Risk Management

Risk management entails more than traditional risk analysis or risk assessment. These traditional tools are limited in fundamental ways, such as the lack of reliable frequency data about past risk events and the relative rarity of many kinds of risk that must still be managed. Risk management involv...

Full description

Bibliographic Details
Main Author: Baskerville, Richard
Other Authors: D W Straub
Format: Book Chapter
Published: M E Sharpe Inc 2008
Online Access:http://hdl.handle.net/20.500.11937/9138
Description
Summary:Risk management entails more than traditional risk analysis or risk assessment. These traditional tools are limited in fundamental ways, such as the lack of reliable frequency data about past risk events and the relative rarity of many kinds of risk that must still be managed. Risk management involves four types of risk treatments: self-protection, risk transfer, self-insurance, and risk avoidance This chapter introduces an approach to risk management in which the risks and risk treatments are strategically managed using a portfolio approach. With a portfolio approach, different risk portfolios are managed through a portfolio of risk treatments.