This is cache of http://feeds.feedburner.com/~r/PracticalRiskManagement/~3/341936763/seven-steps-to-managing-it-risk.html. Cache is the snapshot of article that we took when we index feed.
To see original page click here.
We are not affiliated with the authors of this article and not responsible for its content.
Seven steps to managing IT Risk
2008-07-21 21:34:00 by Ryan Shopp in practical risk management
 
Came across this overview read from a Gartner research note recently. It lays out seven recommended steps managing risk.

  • Implement a framework for risk assessment and mapping.
  • Establish the responsibilities of risk managers with their areas of responsibility.
  • Identify and define the risks to which the business is exposed and what constitutes a risk event or "near miss" so that incidents can be mapped to specific risks.
  • Determine the threat level, and focus on those risks with the highest impact on performance.
  • Establish levels of controls for processes commensurate with the perceived threat.
  • Record and retain risk incident and near-miss information.
  • Conduct periodic risk assessments to determine changes in the operations risk profile and assess control performance.
Great advice. These seven steps are precisely what IT-GRC solutions should help an Enterprise accomplish. They provide the construct (aka think configuration wizard) for establishing and maintaining a quality risk management program. If you have on your company priority list advancing the the risk mitigation/management capabilities or if you've recently been burned, take the time and check out some of our new product demonstration videos. We strive to be transparent around what we offer with our software. That's why our marketing isn't really "marketing" it's live product in action. Come check it out.
 
 
 
 
 
 
TOP SEARCH
Expand / MinimizeClose Widget
  •  
RECENT SEARCH
Expand / Minimize
  •  
RELATED VIDEO
Expand / Minimize
SecurityRatty FAQ
Sergey Zarubin, 31yo
CISSP, CCSP
Moscow, Russia