『Identifying and Estimating Cybersecurity Risk for Enterprise Risk Management』のカバーアート

Identifying and Estimating Cybersecurity Risk for Enterprise Risk Management

プレビューの再生
タイトルを¥1,429で購入し、プレミアムプランに登録する ¥1,330で会員登録し購入
期間限定:2026年5月12日(日本時間)に終了。詳細はこちら。
2026年5月12日までプレミアムプランが3か月 月額99円キャンペーン開催中。
オーディオブック・ポッドキャスト・オリジナル作品など数十万以上の対象作品が聴き放題。
オーディオブックをお得な会員価格で購入できます。
会員登録は4か月目以降は月額1,500円で自動更新します。いつでも退会できます。
オーディオブック・ポッドキャスト・オリジナル作品など数十万以上の対象作品が聴き放題。
オーディオブックをお得な会員価格で購入できます。
30日間の無料体験後は月額¥1500で自動更新します。いつでも退会できます。

Identifying and Estimating Cybersecurity Risk for Enterprise Risk Management

著者: National Institute of Standards and Technology
ナレーター: Tom Brooks
¥1,330で会員登録し購入 ¥1,330で会員登録し購入

30日間の無料体験後は月額¥1500で自動更新します。いつでも退会できます。

30日間の無料体験後は月額¥1500で自動更新します。いつでも退会できます。

¥1,900 で購入

¥1,900 で購入

今ならプレミアムプランが3カ月 月額99円

2026年5月12日まで。4か月目以降は月額1,500円で自動更新します。

概要

All organizations face a broad array of risks, including cybersecurity risk. For federal agencies, the Office of Management and Budget (OMB) Circular A-11 defines risk as “the effect of uncertainty on objectives”. An organization’s mission and business objectives can be impacted by such effects, and must be managed at various levels within the organization. This report highlights aspects of cybersecurity risk management (CSRM) inherent to enterprises, organizations, and systems.

The terms "organization" and "enterprise" are often used interchangeably; however, without an understanding of organizational structure, effective risk management is impossible. For the purposes of this document, an organization is defined as an entity of any size, complexity, or position within a larger organizational structure. The enterprise exists at the top level of the hierarchy where senior leaders have unique risk governance responsibilities. Each enterprise, such as a corporation or government agency, is comprised of organizations supported by systems.

This report describes CSRM activities at each level. Note that there may be iterative levels within the enterprise and that positions may be relative. For example, a given enterprise (e.g., a bureau or corporate division) may represent an organization to the overarching agency or corporation. Enterprise risk management (ERM) calls for understanding the core (i.e., significant) risks that an organization faces, and this document provides supplemental guidance for aligning cyber security risks within an organization’s overall ERM program. Lessons learned from historical cybersecurity incidents demonstrate the importance of collaboration among CSRM and ERM.

PLEASE NOTE: When you purchase this title, the accompanying PDF will be available in your Audible Library along with the audio.

©2021 Tom Brooks (P)2021 Tom Brooks
セキュリティ・暗号化 組織行動 職場・組織行動
adbl_web_anon_alc_button_suppression_c
まだレビューはありません