Monday, July 21, 2008

Seven steps to managing IT Risk

Came across this overview read from a Gartner research note recently. It lays out seven recommended steps managing risk.

  • Implement a framework for risk assessment and mapping.
  • Establish the responsibilities of risk managers with their areas of responsibility.
  • Identify and define the risks to which the business is exposed and what constitutes a risk event or "near miss" so that incidents can be mapped to specific risks.
  • Determine the threat level, and focus on those risks with the highest impact on performance.
  • Establish levels of controls for processes commensurate with the perceived threat.
  • Record and retain risk incident and near-miss information.
  • Conduct periodic risk assessments to determine changes in the operations risk profile and assess control performance.
Great advice. These seven steps are precisely what IT-GRC solutions should help an Enterprise accomplish. They provide the construct (aka think configuration wizard) for establishing and maintaining a quality risk management program. If you have on your company priority list advancing the the risk mitigation/management capabilities or if you've recently been burned, take the time and check out some of our new product demonstration videos. We strive to be transparent around what we offer with our software. That's why our marketing isn't really "marketing" it's live product in action. Come check it out.

Labels: , , , , , , , ,