RESPOND TO THESE DISCUSSION POST BASED ON THE TOPIC ??onsidering all you have learned, what do you see as the cultural, communication, and global challenges facing risk management and risk assessment? As an IT security manager, which of the risks that you identified concern you the most, and why???

In response to your peers, present and discuss each challenge they identified and provide references. In addition, provide mitigating solutions to the challenges you discussed. (TWO (2) PARAGRAPHS EACH WITH REFERENCES ON EACH OF THEM SEPARATELY, NOT TOGETHER)

One of the most worrying issues facing risk management is one that I see as a cultural issue. More of an organizational culture issue really, it seems that many corporations still see their information security systems as being a secondary concern. Something that can be dealt with when a problem arises. This can be difficult for security managers because it means that many security measures are limited by budgets and yes, I realize that would be the case any way. But it seems many companies are fine with cutting corners until a large breach occurs. I think as more and more large-scale breaches occur companies will begin to invest more money into their security systems. Many are already beginning to do this but with the pace technology advances and how slowly a lot of companies are at adopting technology, it seems like a problem that we will be facing for years to come.

One of the biggest challenges is balancing the risk to the organization along with business operations. ?I have always looked a security as a balancing act between the security of a companies data along with the functionality of the business being able to use their data. ?As an IT Security Manager would could lock down all external communication from the internal network to the outside world but this would pose huge challenges to the business being able to communicate and work with outside entities. ?Security decisions should first look at the information that is housed within the organization and determine the impact to the business if this information was compromised. ?Data of sensitive nature should always be kept as secured as possible with limited expose to other systems or the outside world and these communication channels should be monitored and defined to prevent for unauthorized access. ?A security manager should work closely with business leaders to define a security strategy that can both be secure and allow the business to operate without inconvenience. ?One risk I deal with on a monthly basis with my organization is the patching of both business operating systems as well as third party applications. ?Many times OS and third party patching goes by the wayside to accommodate business needs causing my company to become exposed due to identified vulnerabilities that are addressed with these remediation patches.

