Why risk based approach is a better defence?
What is the best approach to address your organisation's information security issues? There are common as well as your business specific Information security threats and mitigation techniques to handle them. For instance, you may already may have staff training, anti-malware and other technologies in place. However, you may not know how effective is your defences until meet a real threat. This requires every organisation to build their defence according to the potential information security risks they might face. So, what actually is a risk-based defence? Your organization does not have an unlimited budget for information security. This requires you to best use available resources carefully to build your defence. The best approach is to conduct a risk assessment, identify risks and prioritize your risks. Then you can implement appropriate controls to mitigate your risks. ISO 27001 ISMS standard provides you a framework to follow a risk-based approach to mee...