ISACA Journal Article
Use of the Balanced Scorecard for IT Risk Management
Risk management, in its essence, is subjective. Though it is a structured approach to determine whether to accept, mitigate, transfer or avoid a risk, it is based on a subjective assessment of the business impact of the exercise on organizational vulnerability.