8.14
Risk Assessment
Principle 8 - Assess Fraud, Improper Payment, and Information Security Risk
Attribute 8.14 - Management considers the types of risks that could impact the entity's information and information technology to provide a basis for identifying and analyzing risks related to information security.62 Information security risk is the risk to entity operations, assets, and personnel, as well as external parties, due to unauthorized access, use, disclosure, disruption, modification, or destruction of information or information technology. These risks may impact the information security objectives of confidentiality, integrity, and availability.63 Types of information security risk impacting each of these three objectives may include the following:
- Unauthorized access - End users, developers, or unrelated attackers may compromise the confidentiality of a platform or software system by overriding controls to gain unauthorized access to the entity's information technology or use capabilities that exceed their rights in those systems.
- Exploitation of personnel - Attacks, such as phishing attempts, that trick users into revealing information or giving an attacker access to a platform or software system.
- Installation of malicious software - Installation of a program or file that intentionally attacks the entity's information technology by corrupting or stealing data, overwhelming a system with traffic, or locking the entity out. The objective of a malicious software (malware) attack may be to harm the entity, gain information, or obtain a financial gain.
- Automated attacks - Attacks on information technology may be automated through mechanisms, such as bots, artificial intelligence, and machine learning software.
- Undetected errors - End users, developers, or unrelated attackers may improperly alter data in the entity's information technology without visible evidence. Erroneous changes resulting from corrupted systems may not be readily detectable by users.
- Threats to physical environment - Threats to the physical environment, such as fire, loss of electricity, loss of climate controls, or natural disasters, can result in the loss of information or information technology system damage or disruption. In addition, failure to appropriately limit physical access to information or an information technology system may also allow a malicious attacker to access or modify information.
>>>Navigational Buttons<<<
- Index of Attributes
- Previous Attribute - ?
- Next Attribute - ?
