ERM
Enterprise Risk Management
ERM is the organization-wide practice of identifying, assessing, and mitigating risks that could affect business objectives. It extends beyond cybersecurity to cover operational, financial, strategic, and reputational risk.
Cómo se usa en ciberseguridad
CISOs and GRC analysts feed cybersecurity risk data into the broader ERM program so executives can compare cyber risk against other business risks. ERM frameworks like COSO and ISO 31000 provide the structure. Security architects use ERM outputs to prioritize control investments.
Las definiciones son explicaciones originales escritas con fines de desarrollo profesional. Para definiciones técnicas autorizadas, consulta NIST, ISO o el organismo de normalización correspondiente.