Managing IT security risks requires the involvement of the
entire organisation, from senior management to the most
junior employee [19]. Figure I demonstrates that an approach
employed to manage IT security risk should encompass risks
from the strategic level down to the business objectives and
processes, likewise the risks from the operational processes up
to the business objectives and strategy [15]. Senior
management is responsible for providing the strategic vision,
goals and objectives of the organisation; mid-level
management is responsible for planning and managing
projects as well as processes; whereas the junior staff IS
responsible for carrying out operational activities [19].
A combination of a top-down approach and bottom-up
approach in managing IT security risk provides a holistic view
of the IT security risk profile, as depicted in Figure 1.
The comparative analysis presented in section IT also
indicates that applying an IT security risk management
framework only at a strategic level of an organisation, may
leave out other significant IT security risks found at tactical
and operational levels of an organisation [15].
The concept of a tiered risk management approach is
recommended to ensure comprehensive coverage of IT
security risks [19]. The tiered risk management approach is