Risk Assessment for Information Technology

Risk Assessment for Information Technology thumbnail
A company may be unable to operate if its Information technology systems are not functional.

Information technology (IT) systems represent the backbone of a corporation's operational infrastructure. Accordingly, a company's top management typically ensures that computer software and hardware mechanisms are adequate, functional and in adherence with regulatory guidelines and industry practices. A risk assessment initiative for IT systems generally helps management understand areas in which significant losses may arise.

  1. Information Technology Risk Defined

    • IT risk consists of breakdowns in computer hardware or IT staff's lack of expertise in a specific field. IT risk also may relate to risk of loss resulting from theft of corporate data or customer information. As an illustration, assume a hacker accesses a bank customer information database. If the bank's IT staff and top leadership do not quickly implement adequate firewall protection measures, the bank may incur losses. IT risk also may be the risk of loss that originates from computer software malfunction, such as a manufacturer's software license expiration or glitches, and how it affects corporate activities.

    Risk and Control Assessment

    • A corporation's top management periodically instructs department heads and segment employees to prepare risk and control self-assessment (RCSA) reports. An RCSA is a document that notes risks and controls related to a process or an area. A control is a set of instructions that a company's management establishes to prevent losses due to technological breakdowns. Employees review IT controls to ensure they are adequate or functional, and then rate risks as "tier 1," "tier 2" and "tier 3" based on loss expectations.

    Time Frame

    • A corporation's senior management typically reviews risk assessment results on a quarterly and annual basis. RCSA and internal audit reports are usually issued every quarter, whereas external auditors present testing results to the board of directors at the end of the year. For example, an IT auditor may review the sales processing and customer service department's internal controls. He may rank risks inherent in the department's activities as "tier 2," or "medium," risks and notify senior management at the end of the quarter.

    Tier 1 Risk

    • "Tier 1" risk, also called "high" risk, is the risk of loss that may emanate from computer system breakdowns in a large business unit. A company's top management typically reviews "tier 1" risks and provides corrective measures. To illustrate, assume a large insurance company cannot process premium payments because IT systems are not functional. The company's board of directors and senior management may hire a consulting firm to remedy the situation or provide temporary mitigating solutions.

    Tier 2 and Tier 3 Risks

    • "Tier 2" and "tier 3" risks are also referred to as "medium" and "low" risks. These risks cause losses in a department's processes or a segment's IT infrastructure. Departmental heads and segment employees typically review "tier 2" and "tier 3" risk events to ensure internal controls are functional and preventing losses. For example, if an insurance company's premium processing department's IT problems only relate to life insurance policies, and the life insurance business unit only contributes 35 percent of total revenues, the company may face a "tier 2" or "tier 3" risk.

Related Searches:

References

  • Photo Credit computers image by Orlando Florin Rosu from Fotolia.com

Comments

You May Also Like

  • Information Technology Risk Assessment Tools

    Information Technology Risk Assessment Tools. Organizations manage their information technology systems to protect against any threats or vulnerabilities. Some businesses ...

  • Risk Management Guide for Information Technology Systems

    Today's businesses face many risks, including natural disasters, intentional and unintentional man-made disasters, and catastrophic systems failures. Any of these ...

  • Information Technology Risks

    Beginning in the early 1980s and accelerating through the Internet revolution of the late 1990s, information technology (IT) has become a critical...

  • Information Technology Assessment Checklist

    Information Technology Assessment Checklist. Information technology assessment plays an integral role in providing a snapshot of your company's computing system. It gives...

  • How to Implement Enterprise Risk Management

    Enterprise risk management (ERM) is a comprehensive approach to risk in business. The process itself consists of multiple steps, however it is...

  • Checklist for a Company Audit

    Checklist for a Company Audit. An audit checklist aids an internal corporate audit department in reviewing company processes, internal controls and human...

  • Information Technology Risk Management Career

    An information technology (IT) risk management specialist evaluates and tests a company's computer hardware and software systems, ensuring that such systems are...

  • Technology Assigned Risk

    All insurance companies rely on computer technology for the processing of claims and managing client information. However, the stakes are raised when...

  • The Definition of Risk Management in Health Care

    In any industry, risk management addresses liability, both proactively and reactively. Risk management in health care considers patient safety, quality assurance and...

  • Internal Control Risks

    Internal Control Risks. Internal controls represent a company's policy for conducting business in a consistent manner, protecting sensitive information relating to ...

  • The Security Vulnerability Assessment for Information Technology

    Information technology officers conduct security vulnerability assessments to find specific holes or vulnerabilities in computer and network systems. Penetration ...

  • Security Self-Assessment Guide for Information Technology Systems

    Managers responsible for information technology systems ensure information security by taking precautionary measures and managing any risks that arise. Assessing ...

  • Risk & Control Self Assessment

    A risk and control self-assessment (RCSA) is a business practice that helps a corporation's top management identify and appraise significant risks inherent...

  • Safety Risk Assessment Procedures

    Safety Risk Assessment Procedures. Developing risk-assessment procedures helps a company or agency study every part of the organization and identify possible exposures...

  • Risk Assessment & Financial Ratios

    Risk assessment plays an essential role in the global marketplace, particularly when it comes to deploying proper strategies to mitigate identified exposures....

  • Technology Assessment in Healthcare

    As technology advances, so do the systems and tools that health care professionals have at their disposal. However, because peoples' health is...

  • Qualitative Risk Assessment Tools

    Risk assessment is identifying the probability that a risk will occur. Qualitative risk assessment tools allow organizations to determine the probability a...

  • Information About Area 51

    What is the best way to keep a secret safe: tell no one, or tell everyone? Area 51 is just that kind...

Related Ads

Featured