III     Common AIO Risk Management Topics

IT systems are designed, built, and implemented to achieve strategic goals and business objectives. While there are risks specific to each of the AIO functions, certain risks are common to all three. Common AIO risk management topics are discussed in the following sections:

  • Data governance and data management.
  • ITAM.
  • Business and IT environment representation.
  • Managing change in AIO and change management.
  • Oversight of third-party service providers.
  • Resilience.
  • Remote access.
  • Personally owned devices.
  • File exchange.

 

Previous Section
II.F Board and Senior Management Reporting
Next Section
III.A Data Governance and Data Management