Home > Risk and trust
Book Chapter:
EMAIL THIS LICENSING & REPRINTS

Risk and trust

25 Aug 2003 | Realtimepublishers.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

This excerpt is from Chapter 2, Identity Management and Security, from the free e-book, The Definitive Guide to Identity Management written by Archie Reed and published by Realtimepublishers.com. Download the e-book at http://www.rainbow.com/insights/ebooks.asp.

When evaluating solutions that enforce security, there is always compromise. Within the security space, this compromise is considered risk management. The reason is that generally the more security you put into place, the less usable the system. In line with that consideration is the acceptance that a system has a value to the organization, which must be secured.

Often the only way to calculate the risk is to use a qualified actuarial representative -- essentially a statistician who computes risks and premiums, generally for insurance policies. Given that this resource is beyond the reach or reality of most organizations, the calculations are done by internal staff as they attempt to define ROI for a project. Calculating such value is different from organization to organization, and project to project, and can involve basic concepts such as the impact of having employees unable to work overtime due to system security breaches, the potential impact of customers (for example, a boycott), or even legal action against the company. Although calculating the value of more physical considerations is fairly easy, determining the cost of service abuse relative to corporate reputation and similar intangible assets can be very difficult. The point is that as you begin to asses the value of the assets that you are trying to protect, it is important that you utilize representatives from across the organization.

Perhaps a more appropriate baseline to begin assessing risk is to ask more generic questions that can be changed as appropriate for your specific situation, along the following lines:

  • How secure is my infrastructure? Is sensitive data protected if disgruntled employees gain access to restricted systems or resources?
  • How secure are my connections beyond my infrastructure? Can you ensure that your high-value online transactions are binding?
  • How secure are my communications within and external to my infrastructure? Are confidential e-mails and files protected from interception by unauthorized employees, competitors and malicious parties?
  • Is there a plan to improve security over time?
  • Is security actually improving over time?
  • Can I transfer risk using different solutions (for example, outsourcing)?
  • How does my security compare with that of similar companies in the industry?
  • How will I respond to a breach in security?

>> Read the rest of this excerpt from Chapter 2, Identity Management and Security


For more information on this topic, visit these resources:


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Risk Management Metrics and Measuring Risk
Consensus Controls project aims to set benchmarks for compliance
Bruce Schenier, Marcus Ranum debate risk management
CIS takes the measure of information security
Security of customer data, IP sustains security budgets
Security visualization helps make log files work
Security data lapses hamper researchers
Next wave of security will be defined by metrics, analysts say
Like MLB scouts, IT security pros are turning to metrics
Interview: Financial Services CISO David Pollino
Failure mode and effects analysis: Process and system risk assessment

Risk Assessment and Analysis
Data risks take shine off Google Chrome
Bruce Schenier, Marcus Ranum debate risk management
PCI is about eliminating data, not securing it, former QSA says.
What role does information security play in enterprise fraud-prevention activities?
Security visualization helps make log files work
Are independent researchers out for fame?
Unified communications trigger data leakage dangers, survey finds
CIO role could shift toward data quality, says IBM group
Security data lapses hamper researchers
Panel: IT governance, risk and compliance program helps reduce expenses

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
risk analysis  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary




Search Additional Security Research and Solutions
Find Security Channel Research for Resellers and Partners
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts