The IT Law Wiki

Enterprise risk management

32,080pages on
this wiki
Add New Page
Add New Page Talk0

Definition Edit

Enterprise risk management is a

comprehensive approach to risk management that engages organizational systems and processes together to improve the quality of decision making for managing risks that may hinder an organization's ability to achieve its objectives.[1]

Overview Edit

"Enterprise risks may arise from internal and external sources. Examples of internal sources include issues such as financial stewardship, personnel reliability, and systems reliability. Where internal risks threaten successful mission execution, enterprise risk management seeks to ensure that internal systems and processes are tailored to minimize the potential for mission failure. Examples of external factors include, but are not limited to, global, political, and societal trends. An organization will modify its enterprise risk management approach to take these risks into account."[2]

Enterprise risk management "[i]nvolves identifying mission dependencies on enterprise capabilities, identifying and prioritizing risks due to defined threats, implementing countermeasures to provide both a static risk posture and an effective dynamic response to active threats; and assessing enterprise performance against threats and adjusts countermeasures as necessary."[3]

References Edit

  1. DHS Risk Lexicon, at 12.
  2. Id.
  3. NICCS, Explore Terms: A Glossary of Common Cybersecurity Terminology (full-text).

Also on Fandom

Random Wiki