protecting that organisation’s part of cyberspace against threats. The team should
approve security goals, policy, assign security roles and co-ordinate and review the
implementation of cybersecurity across the organisation. The head of the team is
accountable for its success. The executive may delegate this responsibility to heads of
department, contractors and individual employees. The multi-disciplinary cybersecurity
team coordinates action on shared risks and sets mandatory requirements for all
stakeholders. Departmental heads are responsible for determining the additional level of
compliance required and convincing the central body that the interpretation is competent.
The organisation should have access to specialist cybersecurity advice. The team should
develop contacts with external cybersecurity specialists or groups including relevant
national authorities and, where appropriate, regional and global organisations.
16.1.2.1.2 Risk Management
Every organisation faces internal and external factors that bring a degree of uncertainty
to whether or not they will achieve its objectives. ISO 31000 regards this uncertainty as
risk. Organisations manage risk by identifying it, analysing it, evaluating the likelihood of
occurrence, determining the potential impacts of the risk materialisation and designing
countermeasures. Organisations should decide whether to modify the risk by treatment
to satisfy the risk criteria (ISO 2009). Similarly, ITU-T regards risk management as about
assessing and quantifying risk and taking action to ensure that residual risk is below
predetermined acceptable levels (ITU 2009f). Recommendation ITU-T X.1055 describes
and recommends the processes, techniques and functional profiles for
telecommunication information security risk management (ITU 2008c). Among other
aspects, the risk management process provides guidance on how to:
Identify risks;
Analyse and evaluate the risks;
Identify and evaluate options for the treatment of risks; and
Select control objectives and controls for the treatment of risks.
This Guide recommends that all organisations adopt solid risk management processes.
Risk management process helps organisations determine what assets need protection,
the threats they require protection against and the controls. The evaluation helps
categorise risks by severity and involves making cost-effective decisions on what needs
protection. The process helps organisations ensure that the efforts and money spent on
security yield cost effective benefits (IETF 1997).
Good risk management processes are not prescriptive. Instead, the processes recognise
that organisations have different business requirements, structures and operational
environments. The process defines broad requirements allowing organisations to decide
the most cost effective and efficient risk management approaches (ISO/IEC 2008). A full
treatment of risk management is outside the scope of this document. ISO/IEC 27005 is
the definitive standard on the topic as it covers concepts such as context establishment,
risk assessment, risk treatment, risk acceptance, risk communication and risk monitoring
and review. ISO/IEC 27005 adopts the PDCA model.
16.1.2.1.2.1 Risk Assessment Model
A risk assessment exercise helps your organisation to produce a list of risks that assets
are facing or is likely to face (ITU 2008c). Thereafter, you should prioritise the risks to
ensure that the more serious one get first attention. Serious risks are the type where the
76