risk management

RSS
  • Symantec record: Two major hacks, two major delays admitting fault, risk to customers

    Posted January 26, 2012 - 2:16 pm

    If your company were hacked in a way that could directly hurt customers, would you announce the worst-case scenario so they could prep while you develop a solution? Or dribble out the news slowly? Symantec dribbled, first with SSL tokens, then source code, leaving customers at risk.
  • What are your risk managers thinking about?

    Posted November 30, 2011 - 4:34 pm

    Security looks at operational risk, but most big companies have officers called risk managers who actually buy insurance policies for the company. What's on their minds? If you run a security operation, you should know, because your work and their work are intertwined.
  • 3 security acronyms to avoid (and 3 to embrace)

    Posted October 13, 2011 - 7:02 am

    Today's security trends are the usual acronym soup. Here are 3 you'd do well to avoid and 3 worth your attention.
  • Hacks make Internet look lawless, but security just hasn't caught up to spear-phishers yet

    Posted June 3, 2011 - 11:09 am

    Data breaches shake confidence in the cloud, blaming it for security gaps between new technology, old security policies and a human tendency toward trust. Fix that and you're golden.
  • Checklist for a successful security assessment

    Posted June 2, 2011 - 10:12 am

    A security assessment is a request to analyze the risk of an IT solution. The request is initiated by a CISO (Chief Security Officer) or ISO (Information Security Officer) within a corporation. It is used to make sure that security concerns are met before changes are made to the information technology infrastructure. There are foundation plans which evaluate the state of new applications or infrastructure. Or there are incremental plans that address changes to the foundation plan.
  • Skype is one more example of why to trust the cloud but wear a parachute

    Posted May 27, 2011 - 9:40 am

    Skype's outage is apparently due to corruption in client-side files -- much different from the cause of outages at Amazon and Azure. The reason doesn't matter; the contingency plan does.
  • Amazon crash reveals 'cloud' computing actually based on data centers

    Posted April 22, 2011 - 2:24 pm

    Hype makes it easy to forget the cloud requires the same skills and includes the same risks as n-tier applications and data-center computing anywhere.
  • Risk management in coud computing

    Posted April 15, 2011 - 8:50 am

    The rewards of cloud computing can be tremendous if the risks are well managed. E-Com Canada's Sri Prakash discusses how best to manage the risk when planning to move assets to the cloud.
  • SAP takes on IBM, Oracle with new GRC suite

    Posted March 23, 2011 - 8:16 am

    SAP is hoping to cement its foothold in the growing market for GRC (governance, risk and compliance) software with a new suite, announced Wednesday, that is nearly three years in the making.
  • Watch out CISOs and CSOs: Chief Risk Officers may be gaining on you

    Posted March 10, 2011 - 12:13 pm

    CSOs and CISOs may feel more pressure from a new breed of security professional - the chief information risk officer - now that the federal government has made risk management mandatory and spelled out in a new document just how risk ought to be assessed and dealt with.
  • Dos and don'ts for IT GRC success

    Posted March 7, 2011 - 8:47 pm

    DO agree on an IT-GRC implementation strategy. Moving disjointed, manual processes into an automated, centralized tool is an enormous undertaking. While a giant boa constrictor can unhinge its jaw and swallow a large mammal whole, that strategy is not advisable for your enterprise.
  • IT GRC tools: Control your environment

    Posted March 7, 2011 - 8:45 pm

    As enterprises approach a high level of maturity in their IT governance, risk and compliance (GRC) programs, they face a conundrum: How can they effectively implement and manage policies and their supporting controls to maintain a strong risk posture? To add to the difficulty, the environments they manage are often widely distributed and subject to multiple regulatory requirements and internal audit requirements, and must adapt to changing business needs. GRC tools are designed to help.
  • eGRC vs. IT GRC

    Posted March 7, 2011 - 8:43 pm

    Most analysts break the market down into two broad categories: IT GRC and Enterprise GRC (eGRC). The vendors generally don't make it any easier for potential enterprise customers, as the IT GRC players often claim they do eGRC, and all the eGRC vendors saying they encompass IT as well.
  • Enterprise risk management - proof or still promise

    Posted February 25, 2011 - 11:04 am

    Although most speak about increased attention to enterprise risk management (ERM) at Board levels, few firms appear to have the organizational prowess and human fortitude to put in place the policies, technologies, and processes to prove out the promise of ERM.
  • 7 cyber crime facts executives need to know

    Posted January 13, 2011 - 11:51 am

    Unfortunately, too many organizations still have their head in the sand when it comes to risk management.
  • Why security pros fail (and what to do about it)

    Posted December 7, 2010 - 9:35 pm

    You've probably heard the phrase, "Failure is the key to success." But are security professionals really learning from their mistakes? As identity theft and online risks keep growing, is our industry rising to the challenge or repeating the miscues of the past? While security technology is improving, the bad guys also have access to better tools. So are the good guys working smarter?
  • Financial services firms failing on risk management

    Posted October 21, 2010 - 11:15 am

    Financial services firms should focus on getting "workable" risk datasets in place to avoid the wrath of regulators, says risk analyst firm JWG.
  • IBM bolsters business analytics unit with purchase of OpenPages

    Posted September 15, 2010 - 10:27 am

    Aiming to expand its business analytics capabilities to support compliance and risk management processes, IBM today announced it is purchasing Waltham, MA-based software vendor OpenPages. Terms of the deal for the privately held company were not disclosed. Naturally, the acquisition is contingent upon regulatory approval.
  • Enterprise risk management: Get started in six steps

    Posted September 7, 2010 - 11:57 am

    Let's say your organization doesn't have a formal enterprise risk management program. If you're at a big company, ERM might seem daunting because of silos, inertia and so on.
  • Enterprise risk management: all systems go

    Posted June 3, 2010 - 8:29 pm

    When Bill Badertscher arrived at Georgetown University three years ago, campuswide security was handled in several departments with little coordination among teams. It was time for a change. Badertscher is Georgetown's senior engineer for facility and safety control systems and leader of a new IT team that focuses on the same areas. The goal is to address enterprise risk management (ERM) by redefining it to include nontraditional systems. Understanding that security is mission-critical has led the University Safety and Information Services departments to work together in unprecedented ways.
  • Security pros, meet your new best friend: the CFO

    Posted April 27, 2010 - 8:50 pm

    Executives in charge of information security should make friends with the CFO, who can give them a broad overview of corporate priorities and see to funding the most important IT projects that protect corporate data.
  • Measuring the health of corporate security

    Posted April 20, 2010 - 2:06 pm

    What does the term 'corporate security' really mean? And how important is it to a company's health? George Campbell explains.
  • Security Consultants and Lawyers: Don't Trust Them to Manage Risks

    Posted April 5, 2010 - 3:13 pm

    Security consultant Scott Wright breaks down the similarities between attorneys and consultants -- and explains why neither can really give you the risk management you need.
  • Information security in health care – four critical errors

    Posted June 4, 2009 - 7:30 pm

    As the first Information Security Manager at a fairly large financial institution, I lived by trial and error for a while. Admittedly, I made mistakes along the way, but the good thing is I learned from them and most of the time put what I learned to use.
  • IT Governance - The Silver Bullet

    Posted June 3, 2009 - 3:16 pm

    Many IT organizations continue to struggle with strategy alignment and demonstrating the value of IT to the business. Recently a group of IT Executives discussed this topic and concluded there was no silver bullet when it comes to IT Governance, or is there?
Ask a Question