Annals of Dunarea de Jos University. Fascicle I : Economics and Applied Informatics (May 2021)
Risks’ Identification and Assessment in a Public Entity Regarding the IT Security Audit
Abstract
This paper highlights the importance and inclusion in the Risk Register of the auditor's opinion regarding reaching of established goals, as well as the awareness of watching any risk that may lead to uncertainty, causing negative effects on those activities, by deteriorating the quality of expected results. Effective risk management assumes that risk identification is a permanent process, which allows the public entity to relate to the procedure of amendment and adaptation. For good risk management at all management levels, the directors of the departments at the first management level appoint those accountable for the menaces. They identify and collect the risks associated to the objectives and / or activities, assumed by the department head and monitor the implementation of risk management.
Keywords