Managing information system-related security and privacy risk is a complex undertaking that requires the involvement of the entire organisation—from senior leaders providing the strategic vision and top-level goals and objectives for the organisation, to mid-level leaders planning, executing, and managing projects, to individuals developing, implementing, operating, and maintaining the systems supporting the organisation’s missions and business functions.
Risk management is a holistic activity that affects every aspect of the organisation including the mission and business planning activities, the enterprise architecture, the SDLC processes, and the systems engineering activities that are integral to those system life cycle processes.