Home > Security Tips > Risk Management Strategies > IT GRC: Combining disciplines for better enterprise security
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

RISK MANAGEMENT STRATEGIES

IT GRC: Combining disciplines for better enterprise security


Khalid Kark
01.16.2008
Rating: -4.08- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


IT governance, IT risk management and IT compliance are three distinct disciplines that in the past have existed in silos within organizations.

Today, many organizations no longer see these activities as individual, one-time projects handled in separate parts of an organization. Many commonalities and interrelationships exist between these three disciplines.

Adopting a unified IT governance, risk management and compliance (IT GRC) approach, and managing the associated activities coherently will create efficiencies, provide a holistic view of the IT environment and ensure accountability.

Defining the components of IT GRC
Business imperatives, increased regulatory pressure and customer demands are forcing many CIOs and CISOs to adopt a structured, enterprise-wide approach to IT GRC. Today, enterprises are acknowledging that a mishmash of technologies and processes working in silos inevitably leads to inefficiency, increased costs and present higher risks to the organization.

There is currently a lot of confusion on what exactly IT GRC is and what subcomponents to consider when establishing a program. Although the specifics of developing an IT GRC program will vary based on the individual circumstances of every organization, having common definitions and broad objectives for each area will establish a high-level approach for the program.

    Want to know more?
For more information on GRC geared specifically toward financial services security professionals, visit our sister site, SearchFinancialSecurity.com.
IT governance establishes decision structures and tracking mechanisms. At its most basic definition, IT governance primarily determines how decisions are made, who makes the decisions, who is held accountable and how the results of decisions are measured and monitored. Although many organizations have some form of IT governance in place, the governance processes are ad hoc, siloed and informal.

Organizations need to first ensure that they have the appropriate governance structures in place; structures such as technology steering committees, architecture review boards and project review boards.

The second step is to ensure that the appropriate processes exist to guarantee consistency and transparency. For example, processes for proposing new projects, approving new IT investments and prioritizing IT projects.

Third, organizations need to ensure that there is appropriate communication and accountability to measure the outcomes of IT decisions, whether these decisions are technical, monitory, human resource, etc.,. Project status reports, ROI analysis and balanced scorecards would be examples of such communication and monitoring.

IT risk management helps mitigate adverse effects and identifies opportunities. IT risk management activities go far beyond traditional IT security responsibilities. As IT environments have become more complex and business reliance on technology has increased, CIO and CISOs are faced with a daunting challenge. Not only are they asked to deal with ever-increasing and multifaceted threats, but they are also challenged to provide increased capabilities within their businesses. That means successfully adapting to changing business needs and enhancing technology capabilities while guarding against adversity. An organization's technology architecture must support this effort though greater flexibility, automation and efficiency.

For more information:
In this Compliance School tip, Richard E. Mackey explains how to approach control and governance frameworks and why they're helpful in mitigating risks.

Contributor Khalid Kark defines the framework behind implementing a successful enterprise risk management plan.
 
Mike Rothman looks back at the key compliance events of 2007, and examines what security professionals can expect for 2008.
IT compliance establishes and monitors IT controls. IT compliance should ensure that an organization is not only adhering to laws and regulations, but is also taking into account corporate responsibilities and industry standards. An organization should also be mindful of corporate intellectual property protection responsibilities and develop a control framework based on industry standards such as COBIT.

Compliance activities include conducting regulatory research, mapping control requirements to regulations, designing IT controls, advising IT and third parties on control requirements and assessing and reporting compliance with regulatory and other requirements.

Many organizations are moving toward a common control framework that can meet multiple regulatory, legal and audit requirements simultaneously. Many software vendors now offer products with built-in mappings for multiple regulations, frameworks and management.

Take a unified approach to align IT GRC initiatives. IT GRC initiatives have traditionally been scattered across organizations without any coordination or synchronization. It's not uncommon for different business areas to develop their own solutions for the same requirement or for IT to deploy multiple technologies to address a common issue. These separate initiatives create inefficiency and make it very hard to assess and manage risks holistically.

"IT governance primarily determines how decisions are made, who makes the decisions, who is held accountable and how the results of decisions are measured and monitored.
As a result, there is a growing demand for products that help IT organizations effectively break down these silos and create a centralized approach to managing risk and compliance while simultaneously ensuring good governance.

Ensuring IT GRC success
To make an IT GRC program effective, CIOs and CISOs need to:

  • Understand dependencies and provide a common approach. Governance, risk and compliance functions depend on each other to be successful. The governance program measures against the control frameworks and IT compliance requirements to implement the IT strategy. The compliance program utilizes IT and business risks to rationalize the controls it needs to execute and maintain. Finally, the risk program determines risks based on IT governance activities and utilizes control activities and measurements from the compliance program to determine the existing risk profile for an organization. All three programs running in parallel, but in coordination with each other, are required for an effective GRC program.

  • Unify controls for IT risk and compliance. The processes for identifying and reporting IT risk and IT compliance may be different, but a common control framework can be to establish and measure security controls. Establishing a common control framework that fulfills the internal and external compliance requirements, while managing IT risk to corporate resources reduces duplication of effort, ensures consistency and breaks down the silos.

  • Enable IT governance by establishing accountability. Establishing accountability is an essential part of an IT GRC strategy that many organizations struggle with. The first step for establishing accountability is to ensure that roles, responsibilities, governance structures and processes are clearly articulated, communicated, and understood by a board of directors, executive management, business management, IT management, employees and shareholders. The second step is to ensure appropriate measurement and reporting mechanisms are in place in order to monitor and measure critical areas and adjust the course based on those measurements.

  • Align technology and processes for efficiency and consistency. Although technology plays an important part in automating, aggregation, analysis and reporting of IT controls, it's not the only ingredient CIOs and CISOs need to establish a core set of processes and define touch points between IT governance, risk and compliance activities. Once those processes are established, only then can technology help automate and augment those processes.

    Coordinating and pushing a coherent IT GRC approach across different parts of the organization requires significant effort and persistence. The benefits may not be evident right away, but having a structured program ensures long-term benefits such as enhancing IT governance capabilities, helping mitigate IT threats more effectively and simplifying regulatory compliance.

    About the author
    Khalid Kark is a principal analyst at Forrester Research where he contributes to its offerings for security and risk management professionals. He is a leading expert in security management, compliance, best practices and services. For more information on Khalid or to review additional research, please visit: www.forrester.com/rb/analyst/khalid_kark.

    Rate this Tip
    To rate tips, you must be a member of SearchSecurity.com.
    Register now to start rating these tips. Log in if you are already a member.




    BROWSE BY TAG
    Risk Management Strategies,   Information Security Policies, Procedures and Guidelines,   Information Security Management,   Business Management: Security Support and Executive Communications,   VIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



    RELATED CONTENT
    Risk Management Strategies
    Cloud computing in 2010: Be ready for risk management challenges
    How to justify information security spending on cloud computing
    How to protect distributed information flows
    Black box and white box testing: Which is best?
    Breach prevention: How to keep track of data and applications
    Information security management hype: Debunking best practices
    Monitoring program data and internal controls for risk management
    Cloud computing security: Choosing a VPN type to connect to the cloud
    Cloud computing security: Routing and DNS security threats
    Cloud computing security model overview: Network infrastructure issues

    Information Security Policies, Procedures and Guidelines
    Schneier-Ranum face-off part 6: Audience questions
    Editor's Desk: Apathy and the Cybersecurity Coordinator
    Writing security policies using a taxonomy-based approach
    How to detect and respond to money laundering
    Health Net breach failure of security policy, technology
    How to protect distributed information flows
    Whitelists, SaaS modify traditional security, tackle flaws
    Melissa Hathaway urges more cooperation, government attention to cybersecurity
    Reuters: Obama ready to select cyber security czar
    How a corporate Twitter policy can combat social network threats

    Business Management: Security Support and Executive Communications
    Schneier-Ranum face-off, part 3: Compliance and security
    Cost of security, IT management add up at healthcare facilities, study finds
    Secure your remote users in 2010
    Layoffs prompt insider threat fears, cybersecurity survey finds
    How to use Internet security threat reports
    Aligning network security with business priorities
    IT business justification to limit network access
    RSA council addresses growing security risks in the cloud
    How to write a risk methodology that blends business, security needs
    Risk management must include physical-logical security convergence

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    defense in depth  (SearchSecurity.com)
    non-disclosure agreement  (SearchSecurity.com)
    security policy  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary

    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



  • Research Solutions for Network Security, Access Control and Security Threats
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2010, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts