What Is Risk Management in Network Security? 

What Is Risk Management in Network Security? 

Risk management in network security is the process of identifying, assessing, prioritizing and mitigating risks to network infrastructure, data and services from threats and vulnerabilities. While it is impossible to eliminate risk, it is possible to manage risk to an acceptable level. This process starts with an organization defining three (3) crucial components of risk management:

  1. Risk Tolerance;
  2. Risk Threshold; and
  3. Risk Appetite.

To “manage an organization’s risk, ” that organization needs to adhere to its  stated risk tolerance, where the organization has four (4) options to address identified risks:

  1. Reduce the risk to an acceptable level;
  2. Avoid the risk;
  3. Transfer the risk to another party; or
  4. Accept the risk.