ISRM Short Notes
ISRM Short Notes
ISRM Short Notes
Viraj Dissanayake
Financial risk
Information management risk
Other
Identification
Qualitative analysis
Quantitative assessment
Response planning
Monitoring & controlling
IT governess
Requirements
o Appropriate structure
o Placing processes in planed manner
o Proper communication
o Accountability
IT Risk management
Requirements
o Operational approach
o Technology
o Partnering
IT Compliance
Objective
1|Page
o Cooperate compliance
o Best practice
o Legal
COBIT 5 Principles
FISMA (Federal Information Security Management) – An act implemented to protect Federal IS. Purpose
is to protect critical information infrastructure
Target Audience
Oversight responsibility for risk management – CEO
Responsibilities for conducting organizational missions/business functions – Manager
Information security oversight, management, and operational responsibilities –CIO, CISO
Information security assessment and monitoring responsibilities – evaluators, auditors
Responsibilities for acquiring information technology products, services, or information systems
– procurement officer
Information system/security design, development and implementation responsibilities –
architect, program manager
2|Page
Three tiers
Organization (governess)
Business process
Information system
Frame
Assess
Respond
Monitor
3|Page
4|Page
ISO COSO
The standard doesn't specify, recommend or even name any specific risk management method
Steps in ISO27005
Residual risk – the risk value we get after applying a risk treatment option
COSO ERM Cube consists of Business objectives, ERM Components, Business structure
strategic
operation
reporting
compliance
5|Page
There are 8 components in COSO ERM Framework
Objectivity
Easy to present the results
Direct cost projection
Root cause analysis (RCA) - Method of identifying root cause of the problem
RCA techniques
Five whys
Fish bone
6|Page
Business continuity planning – Activities required to keep organization running without the normal
operations
Business continuity can be proceeded only if the disruption or disaster is a mild one, not a severe one
7|Page