196k views
5 votes
_____ information system operation based on a determination of the risk to organizational operations and assets, individuals, other organizations, and the Nation resulting from the operation of the information system and the decision that this risk is acceptable.

1 Answer

4 votes

Final answer:

The statement in question pertains to the acceptance of some level of risk in the operation of an information system, which is a critical component of strategic decision-making within organizations and states, as observed in security operations centers.

Step-by-step explanation:

The phrase in question refers to the acceptance of risk in information system operations. This is a concept where a decision is made to operate an information system with the understanding that there is some level of risk involved. The risk is evaluated against the potential rewards or benefits that the operation of the system might bring.

Decisions of this nature are paramount in states' strategic decision-making processes, relying heavily on information at hand which can include intelligence data on another state's intentions. In the context of information security centers, such as that of a banking institution's, research like the one by Bruno & Abrahão (2012) has shown that the number of decisions operators make can impact the accuracy of identifying real vs.

false security breaches. This phenomenon was also evident in the case of the Target data breach in 2013, suggesting a direct correlation between cognitive demand and decision accuracy in high-pressure environments like security operations centers.

User Nikkole
by
7.7k points