SlideShare a Scribd company logo
Rev2 IT Information SecurityRisk ManagementFebruary 26, 2010
Today’s DiscussionAgendaRev2 IntroductionRiskView FrameworkExamplesNext StepsGoalsIntroduce RiskViewTMa decision support system which helps identify and focus on business-material risksUnderstand your risk-management focus areas & processes2
Rev2 Risk ManagementInfoSec RiskSupply Chain RiskService Delivery RiskRiskView replaces ad-hoc processes with aFact-based, Scalable, Repeatable FrameworkIdentify under controlled risk via business viewsFocus on the most material drivers“What-if” controls testing
ButBig ExposurePlenty of DataInfo sec tools and services regularly identify 100,000’s vulnerabilitiesTodayRiskView provides a fact-based, scalable, repeatable process4Most companies collect large vulnerability data sets, but face big material risk in information security. Because…Reactive response
Perception vs. facts
Wasted money
On-going vulnerabilityValue is limited by…Data silos
Inconsistent data
Wrong metrics
Changing process
Inadequate toolsHow do you prioritize 1 Million vulnerabilities?
StructureSystemsToolsInfo Sec Risk Mgt requires a formal strategy and organization approachAn on-going formal process is needed to meet  goals and execute strategySpecial tools are required to consistently and efficiently analyze large data setsKey Elements IncludeLeadership– To coordinate across business units
Metrics—Consistent metrics for materiality of business impact
Risks and Policies—To identify risks and define policies to limit exposure
Compliance—Regular evaluations to learn policy compliance and violations
Risk Updates—Regular reviews for materiality score changes
Measures and Actions—Regular risk assessments with next steps to fix key findings

More Related Content

PDF
Embedding RCSA into Strategic Planning and Business Strategy
PPTX
Presenting Metrics to the Executive Team
PDF
Infographic - Critical Capabilities of a Good Risk Management Solution
PDF
Integrated Risk Management
PDF
Enterprise Risk Management
PDF
App Showcase: Enterprise Risk Management
PDF
App Showcase: Compliance
PDF
'Re-writing' Infrastructure management
Embedding RCSA into Strategic Planning and Business Strategy
Presenting Metrics to the Executive Team
Infographic - Critical Capabilities of a Good Risk Management Solution
Integrated Risk Management
Enterprise Risk Management
App Showcase: Enterprise Risk Management
App Showcase: Compliance
'Re-writing' Infrastructure management

What's hot (20)

PPTX
Third Party Risk Management
PDF
ERM Benchmarking Survey Results
PDF
Hello ERM - It's Time to Go
PDF
Data Driven Risk Management
PDF
An Intro to Core
PDF
Third-Party Risk Management (TPRM) | Risk Assessment Questionnaires
PPT
Development and implementation of metrics for information security risk asses...
PPTX
Allgress High Level Presentation
PDF
Third Party Risk Management Introduction
PDF
Spreadsheets vs Software for SOX Compliance
PDF
The Risk Paradox: Showcasing the Success of Security
PPTX
Compliance Management Software | Corporate Compliance
PDF
The Security Practitioner of the Future
PDF
Why Corporate Security Professionals Should Care About Information Security
PPTX
Hernan Huwyler - 10 risk concepts to throw on the bonfire
PDF
Protect Yourself from Cyber Attacks Through Proper Third-Party Risk Management
PDF
App Showcase: Retail Loss Prevention
PDF
Safety & Asset Integrity Excellence - A Study of Three Mile Island
PDF
third party risk management best practices
PDF
Directory: Regulatory & Risk Data
Third Party Risk Management
ERM Benchmarking Survey Results
Hello ERM - It's Time to Go
Data Driven Risk Management
An Intro to Core
Third-Party Risk Management (TPRM) | Risk Assessment Questionnaires
Development and implementation of metrics for information security risk asses...
Allgress High Level Presentation
Third Party Risk Management Introduction
Spreadsheets vs Software for SOX Compliance
The Risk Paradox: Showcasing the Success of Security
Compliance Management Software | Corporate Compliance
The Security Practitioner of the Future
Why Corporate Security Professionals Should Care About Information Security
Hernan Huwyler - 10 risk concepts to throw on the bonfire
Protect Yourself from Cyber Attacks Through Proper Third-Party Risk Management
App Showcase: Retail Loss Prevention
Safety & Asset Integrity Excellence - A Study of Three Mile Island
third party risk management best practices
Directory: Regulatory & Risk Data
Ad

Viewers also liked (8)

PPT
A coach szerepe a változásmenedzsmentben kremmer laszlo
PPTX
Docência Online e seus processos de formação contemporâneos
PDF
Eloadasanyag Nemzetkozi Penzugyi Rendszer
PPTX
Hotel Boscolo Budapest
DOC
Tematika vezetoi szamvitel_-_2010. tavaszi félév
PDF
jQuery Behaviours
PDF
Az éves beszámoló
A coach szerepe a változásmenedzsmentben kremmer laszlo
Docência Online e seus processos de formação contemporâneos
Eloadasanyag Nemzetkozi Penzugyi Rendszer
Hotel Boscolo Budapest
Tematika vezetoi szamvitel_-_2010. tavaszi félév
jQuery Behaviours
Az éves beszámoló
Ad

Similar to Risk View - InfoSec intro (20)

PPT
ERM Presentation
PPT
RiskWatch for Financial Institutions™
PDF
An Intro to Resolver's InfoSec Application (RiskVision)
PDF
Microsoft InfoSec for cloud and mobile
PPT
Review of Enterprise Security Risk Management
PPTX
IAS101REPORTINGINFORMATIONRISKBSIT3B.pptx
PPTX
REPORTING IAS101djfjfjffjfjfjjfjfjjf.pptx
PPT
Risk Management (1) (1).ppt
PPTX
Risky Business
PPT
ENTERPRISE risk management AWARENESS.ppt
PDF
Defense In Depth Using NIST 800-30
DOCX
case studies on risk management in IT enabled organisation(vadodara)
DOCX
CHAPTER 1Risk Management FundamentalsCopyright © 202
PPT
Risk1.ppt
PPTX
crisc_wk_3.pptx
PPTX
PRINCIPLES-OF-RISK-AND-MANAGEMENT.pptx
PPT
RiskWatch for Physical & Homeland Security™
PPTX
Managing Information Risk in Financial Services
PPTX
2_IT Risk Starter Kit - How To Guide.pptx
PPTX
CISSP Chapter 1 Risk Management
ERM Presentation
RiskWatch for Financial Institutions™
An Intro to Resolver's InfoSec Application (RiskVision)
Microsoft InfoSec for cloud and mobile
Review of Enterprise Security Risk Management
IAS101REPORTINGINFORMATIONRISKBSIT3B.pptx
REPORTING IAS101djfjfjffjfjfjjfjfjjf.pptx
Risk Management (1) (1).ppt
Risky Business
ENTERPRISE risk management AWARENESS.ppt
Defense In Depth Using NIST 800-30
case studies on risk management in IT enabled organisation(vadodara)
CHAPTER 1Risk Management FundamentalsCopyright © 202
Risk1.ppt
crisc_wk_3.pptx
PRINCIPLES-OF-RISK-AND-MANAGEMENT.pptx
RiskWatch for Physical & Homeland Security™
Managing Information Risk in Financial Services
2_IT Risk Starter Kit - How To Guide.pptx
CISSP Chapter 1 Risk Management

Risk View - InfoSec intro