Risk Management

Risk Management

ARIN employs a structured, ongoing process to identify, analyze, evaluate, and mitigate business risks.

Click on each link to expand/for more information

ARIN employs a comprehensive Risk Management Program that manages business risks across the entire organization.

The Risk and Cybersecurity Committee provides recommendations and oversight to ARIN’s security program.m»Learn more

An authenticated and unauthenticated penetration test and external vulnerability assessment is performed annually to identify security vulnerabilities. Issues identified are classified according to risk, analyzed, and remediated.

A security training program is in place to make all personnel aware of our information security policies and procedures and their role in protecting systems, data, and personnel.

Sensitizes staff to the threat in their Inbox and conditions them to identify and report suspected attacks. ARIN runs monthly phishing scenarios that enforce desired user behaviors in a non-punitive manner.

The set of rules ARIN follows to evaluate, monitor, and mitigate the risks associated with third-party suppliers and contractors across the engagement lifecycle.

We periodically engage an independent firm to conduct a full review and audit of the Registration Services Department’s processes and procedures to ensure consistency with the policies described in the Number Resource Policy Manual (NRPM), including in areas such as Internet number resource allocation and fraud detection and prevention. »Learn more