In: Computer Science
1. What are the benefits of writing a change management policy? Why is an understanding of risk and risk management so important to an effective and successful information security program? Support your answer with material from the eText or the academic literature.
Benefits of change management
* Reduce the time needed to implement change
* Change Management Lowers the Chances for Project Failure
* Reduce stress and anxiety associated with change
* Plan and execute an effective communication strategy
* Change management allows the organization to assess the overall impact of a change
* Maintain the routine in the running of your business during change
Risk and risk management in an effective and successful information security program
Information security risk management, is the process of managing the risks associated with the use of information technology. In other words, organizations identify and evaluate risks to the confidentiality, integrity and availability of their information assets.
Actions taken to remediate vulnerabilities through multiple approaches:
Risk acceptance
Risk avoidance
Risk management
Incident management
Incident response planning
Best practices include:
* Implement technology solutions to detect and eradicate threats
before data is compromised.
* Ensure compliance with security policies.
* Make data analysis a collaborative effort between IT and business
stakeholders.
* Ensure alerts and reporting are meaningful and effectively
routed.
A complete IT security assessment and managing enterprise risk is essential to identify vulnerability issues.
Practice shows that a multi-phased approach to creating an ISRM program is the most effective, as it will result in a more comprehensive program and simplify the entire information security risk management process by breaking it into several stages. It will make the ISRM process more manageable and enable you to fix issues more easily.
*****************************************************************************************************************************
All the Best !!