The impact of security risk analysis lies in the risk management/security management practitioner’s ability to influence ‘management’ accordingly.
‘Management’ – the people appointed as managers, as opposed to the idea of the management activity or function. This is about influencing those people and what risk analysis will do for them.
Four points to consider;
- Contributes or adds to a problem ‘definition’ and works to achieve a greater deeper understanding of the working or operating environment being looked at or studied.
- Requires deliberate consideration of a wide range of factors that contribute to the risk exposure, as part of the analysis. (Managers must be engaged with the analysis to consider asset criticality and the consequences of any loss event)
- The analysis helps achieve a categorization or prioritization of the risks involved.
- Risk Analysis provides support for the basis of informed decision-making, even if later on there are comprises on your mitigation selections and techniques.
It is a tool that doesn’t prohibit or stop a business from taking risks. It facilitates the business while having contingencies in place to minimize potential damage and losses.
