Yurchuk Natalia – Candidate of Economic Sciences, Associate Professor of the Department of Computer Science and Economic Cybernetics, Vinnytsia National Agrarian University (21008, 3 Sonyachna st, Vinnytsia, е-mail: urnata@vsau.vin.ua).
The features of modern information risk management are considered and analyzed in the article. The influence of digitalization of enterprises on information security is analyzed.
Approaches to the interpretation of the definition of "information risk" are analyzed. It is indicated that information risks arise primarily from the creation, transmission, storage, processing, use of information in practical activities using digital media and other information and communication means. The purpose of risk management of information risks of the enterprise is to minimize the costs of counteracting information risks and the overall losses from them. Information risks include risks of internal and external fraud, unauthorized use of company resources, breach of confidentiality, integrity and reliability of information, etc.
The proposed information risk management system provides for the implementation of such procedures as identification of information risks, analysis of information risks, selection and implementation of the method of reducing information risks, control of information risks.
It has been found that it is advisable to use models based on international standards when modeling information threats. Popular practices used in practice are based on standards such as ISO / IEC 27005: 2011, NIST SP800-30, EBIOS, OCTAVE.
It is determined that quantitative calculation of risk situations is used first of all when it is necessary to choose the optimal variant of solving a risk situation. Enterprise information risk management techniques include organizational and technological measures.
It is established that the methods of information risk management of the enterprise include organizational and technological measures. Organizational methods of risk reduction include: risk aversion, loss prevention, loss minimization, transfer of risk control, risk sharing method, information seeking, control or risk management. Technology measures include the accumulation of risk information, their assessment and analysis, ranking and informing management about the implementation of risks and the likelihood of their occurrence, the use of modern data protection systems (obstruction, access control, masking, regulation, etc.).
It is established that the choice of information risk management methodology in each individual case depends on the specific activity of the enterprise.
