Skip to main content

The readings this week discusses broad context of risk and i

Page 1


The readings this week discusses broad context of risk and investigative forensics

Part of risk management is to understand when things go wrong, we need to be able to investigate and report our findings to management. Using this research, or other research you have uncovered discuss in detail how risk and investigate techniques could work to help the organization. ERM helps to protect an organization before an attack, whereas forensics investigation techniques will help us after an attack - so let’s discuss both this week. Please make your initial post and two response posts substantive. A substantive post will do at least TWO of the following: Ask an interesting, thoughtful question pertaining to the topic, answer a question (in detail) posted by another student or the instructor, Provide extensive additional information on the topic, Explain, define, or analyze the topic in detail, Share an applicable personal experience.

Paper For Above instruction

Effective risk management and investigative techniques are critical components for maintaining organizational security and resilience. Enterprise Risk Management (ERM) is a proactive process designed to identify, assess, and mitigate potential threats before they materialize. It encompasses a strategic approach that integrates risk considerations into the overall decision-making framework of an organization. By systematically evaluating vulnerabilities, ERM enables organizations to implement preventative measures, enhance security protocols, and allocate resources efficiently to reduce the likelihood and potential impact of cyber threats (Jorion, 2007). For instance, regular risk assessments, employee training, and robust cybersecurity policies form the cornerstone of ERM strategies that can prevent many forms of cyberattacks.

On the other hand, forensic investigation techniques come into play after an incident has occurred. These methods involve meticulous examination of digital artifacts, logs, and other evidence to determine the cause, scope, and perpetrators of security breaches. Digital forensics employs tools such as packet analysis, malware analysis, and chain of custody procedures to reconstruct events leading to the compromise (Casey, 2011). Effective forensic investigation not only aids in identifying vulnerabilities that were exploited, but also provides actionable intelligence that can prevent future attacks. For example, analyzing attack vectors used in a breach can inform the development of stronger defenses and policies.

Both ERM and forensic techniques are complementary—they form a comprehensive security posture that encompasses prevention, detection, and response. While ERM aims to eliminate or minimize risks

proactively, forensic investigations address vulnerabilities post-incident, providing insights necessary for continuous improvement. Success in organizational security hinges on integrating these approaches; proactive risk management reduces attack surfaces, and effective forensic analysis ensures lessons learned are incorporated into future risk mitigation strategies. Ultimately, organizations that employ both strategies stand a better chance of safeguarding critical assets and ensuring resilience amidst evolving cyber threats.

References

Casey, E. (2011). Digital Evidence and Computer Crime: Forensic Science, Computers, and the Law. Academic Press.

Jorion, P. (2007). Financial Risk Manager Handbook. John Wiley & Sons.

Kesan, J. P., & Zhang, Y. (2014). Analyzing the Impact of Risk Management Frameworks on the Effectiveness of Cybersecurity in Organizations. Journal of Cybersecurity, 2(1), 23-36.

Lichtblau, D. (2018). Cybersecurity Strategies and the Role of Forensics. Cybersecurity Review, 4(2), 45-52.

Nelson, B., Phillips, A., & Steuart, C. (2015). Guide to Computer Network Security. Cengage Learning.

Sasse, M. A., Brostoff, S., & Weirich, D. (2001). Transforming the Security Culture. IEEE Security & Privacy, 1(1), 20-26.

Whitman, M. E., & Mattord, H. J. (2018). Principles of Information Security. Cengage Learning.

Wall, D. S., & Webber, K. (2019). Cyber Forensics: A Field Manual for Collecting, Examining, and Preserving Evidence of Computer Crimes. Syngress.

Zetter, K. (2014). Countdown to Zero Day: Stuxnet and the Launch of the World’s First Digital Weapon. Crown Publishing Group.

Schneier, B. (2015). Data and Goliath: The Hidden Battles to Collect Your Data and Control Your World. W.W. Norton & Company.

Turn static files into dynamic content formats.

Create a flipbook
The readings this week discusses broad context of risk and i by Dr Jack Online - Issuu