An Introduction To
Information, Network and Internet Security

Show table of contentsGlossary

Hazard Risks

Risk

Description

Internal / External

Contract Risk

Risk stemming from the terms agreed within a contract or the failure to have a contract in place to protect the interests of the parties. Often contract are signed without one side actually understanding what they mean or they are entered into by default (i.e. internet contracts or verbal ones)

Internal

Cultural Risk

Failure to deal with cultural issues affecting employees, customers or other stakeholders. These include language, religion, morality, dress codes and other community customs and practices

External

Facilities and Operating Environment Risk

Loss or damage to operational capabilities caused by problems with premises, facilities, services or equipment.

Both

Geo-political Risk

Loss or damage in some countries, caused by political instability, or by poor quality of infrastructure in developing regions, or by cultural differences and misunderstandings

External

Human Resources Risk

Failure to recruit, develop or retain employees with the appropriate skills and knowledge, or to manage employee relations

Internal

Natural Events

The risk of natural vents that are generally unforeseen affecting the business (e.g. Tsunami 1994)

External

Products and Services

The risk that the wrong product or service is being offered or that the price is wrong. This usually comes from failure to undertake proper market research or rapidly moving markets that have not been tracked so that the risks. This is often a symptom of failure to ensure that risk is a 'living' process.

Internal

Supplier Risk

Failure to evaluate adequately the capabilities of suppliers leading to breakdowns in the supply process or sub-standard delivery of supplied goods and services. Also failure to understand and manage the supply-chain issues

External

 



The Security Practitioner

An Introduction to Information Security