International Electrotechnical Commission
Glossary

ENRisk Management 
The process of managing risks to agency operations (including mission, functions, image, or reputation), agency assets, or individuals resulting from the operation of an information system. It includes risk assessment; cost-benefit analysis; the selection, implementation, and assessment of security controls; and the formal authorization to operate the system. The process considers effectiveness, efficiency, and constraints due to laws, directives, policies, or regulations.

TC/SC:57Terms     Info     Publications
Published in:IEC 62351-2, ed. 1.0 (2008-08) Terms     Info
Reference number:2.2.163
Source:NIST SP 800-30

© Copyright 2024 IEC, Geneva, Switzerland. All rights reserved