Risk assessment and mitigation
Risk assessment and mitigation are critical parts of an enterprise risk management plan. Review information from the NIST article and write a 750 words with APA-formatted paper summarizing the article. Focus your paper on the following key areas:
Risk tolerance and risk appetite
Impacts of threats and vulnerabilities on enterprise assets
The creation of risk registers outlining the likelihood and impact of various threats
Risk response and monitoring
Article:
Sample Answer
Summary of the NIST Article on Identifying and Estimating Cybersecurity Risk for Enterprise Risk Management (ERMI)
Risk Tolerance and Risk Appetite
Risk tolerance is the amount of risk that an organization is willing to accept. Risk appetite is the organization’s willingness to take on risk in order to achieve its goals.
Risk tolerance and risk appetite are important factors to consider when developing an enterprise risk management plan. An organization that is too risk-averse may not be able to achieve its goals, while an organization that is too risk-tolerant may be at risk of serious consequences if something goes wrong.
Impacts of Threats and Vulnerabilities on Enterprise Assets
Cybersecurity threats can have a significant impact on enterprise assets. These assets include information, systems, and people.