From the course: ISACA Certified Information Systems Auditor (CISA) Cert Prep
Unlock this course with a free trial
Join today to access over 25,300 courses taught by industry experts.
Enterprise risk management
From the course: ISACA Certified Information Systems Auditor (CISA) Cert Prep
Enterprise risk management
- [Instructor] All right, let's talk a little bit about risk management throughout the enterprise. So we need a risk management framework to follow, and the one that I've picked out to look at is NIST 800-39. And this particular framework, or standard, if you will, discusses implementing security and risk management within or at the organizational, mission, and information system view. So ultimately, it addresses the three tiers of the organization. You have the needs of the organization as a whole. We're talking strategic goals so that we can satisfy those stakeholder needs. Then we have mission goals. You can think of those as project goals where we have individual projects that are designed to help us meet the goals and objectives of the business. And then, at the bottom, and that's for a reason, last, we look at the information system view. The information systems support the mission, the mission supports the organization. So NIST 800-39 lays out essentially the elements of the…
Practice while you learn with exercise files
Download the files the instructor uses to teach the course. Follow along and learn by watching, listening and practicing.
Contents
-
-
-
(Locked)
Enterprise risk management8m 30s
-
(Locked)
Introduction to IT governance8m 46s
-
(Locked)
IT frameworks9m 20s
-
(Locked)
Frameworks continued11m 38s
-
(Locked)
Enterprise architecture4m 55s
-
(Locked)
Evaluation of controls3m 36s
-
(Locked)
Evaluation criteria8m 11s
-
(Locked)
Information security strategy8m 9s
-
(Locked)
Information security program6m 44s
-
(Locked)
Quality control and security management3m 40s
-
(Locked)
Roles and responsibilities7m 7s
-
(Locked)
-
-
-