Risk control: A technical view

Piers Wilson · Computer Fraud & Security · 2005

Risk assessments offer recommendations that are often too basic for IT security professionals. On the other hand technical staff often lack business knowledge. This means that key controls are often ignored. Assessments are increasingly becoming mainstream business concerns with the rising significance of corporate governance. Both business and technology aspects must be intrinsically linked in formulating assessments in this current climate. The relationship between the technical aspects of IT security and ‘risk assessment’ has always been somewhat variable and, in many cases, non-existent. The reasons for this are often diverse and fault can be attributed to both sides of any discussion. In the author's experience, there are three main reasons for this loggerhead - risk assesments often state the obvious, there is lack of business awareness in the technical disciplines and accounting or discounting of existing controls.

Read the paper · More papers on PaperTik