A KISS Approach to Enterprise Security Risk Management

Enterprise security risk management (ESRM) has been a topic of increasing interest for security managers over the past few years, and ASIS International has identified it as a strategic focus. But a review of the literature, beginning with the 2010 CSO roundtable paper on ESRM, raises two issues that could make ESRM implementation difficult. First, … Continue reading A KISS Approach to Enterprise Security Risk Management

Integrating a Risk Management System into Your Organization

Integrating a risk management system into your department or organization will be a major endeavor and while there are significant benefits to making this change, the degree of effort required should not be underestimated. Moreover, the overall workload of the organization and other major initiatives that might also be underway are major considerations when planning … Continue reading Integrating a Risk Management System into Your Organization

Risk assessments grading and metrics

risk assessment grading

When we are conducting a risk assessment, we need a way to assess, grade and order risks to allow us to use this information for decision-making and to prioritize our actions. This article outlines some basic techniques that can be used for risk assessment grading and matrics.  These basic examples lay the foundation for more complex sets of metrics … Continue reading Risk assessments grading and metrics

The risk assessment process – how to conduct a risk assessment

The risk assessment lies at the core of risk management.  Without a clear understanding of the risks faced, none of the other risk management activities can be undertaken meaning that the organization will remain reactive instead of being able to take proactive steps informed by risk-based decision making.  However, risk assessments have the potential to become hugely … Continue reading The risk assessment process – how to conduct a risk assessment