Archive - November 2000

Transferring Information Security Risk with Cyber Insurance

Eric Vanderburg

Transferring Information Security Risk

There are four ways of dealing with risk; Avoid, Mitigate, Accept, or Transfer.  Avoiding a risk would involve changing procedures or systems so that the risk does not apply anymore such as removing old encryption protocols so that their risk is avoided.  Risks are mitigated by implementing security controls.  If the risk is within acceptable levels it can be accepted and lastly risks can be transferred, primarily through insurance.

Read More