ISA Protection of Information B17-172x

Explain the starting point for assessing cyber risk

Assessing cyber risk begins with an understanding of which information systems are most valuable to an organization and why they are important to the achievement of the organization’s objectives.  Unless management understands which systems are critical to organizational objectives and which are not, it will under-allocate resources to mission-critical systems and over-allocate resources to unimportant systems