ERM
Enterprise Risk Management
ERM is the organization-wide practice of identifying, assessing, and mitigating risks that could affect business objectives. It extends beyond cybersecurity to cover operational, financial, strategic, and reputational risk.
Como é usado em cibersegurança
CISOs and GRC analysts feed cybersecurity risk data into the broader ERM program so executives can compare cyber risk against other business risks. ERM frameworks like COSO and ISO 31000 provide the structure. Security architects use ERM outputs to prioritize control investments.
As definições são explicações originais escritas para fins de desenvolvimento profissional. Para definições técnicas autoritativas, consulte NIST, ISO ou o órgão de normalização correspondente.