Convergence: A holistic approach to risk management
Kent R. Anderson · Network Security · 2007
All too often, security practitioners tend to think about security purely as a logical issue. Locking down firewalls and structuring access to user accounts is only one part of the puzzle, however; other aspects of security are just as important in the enterprise. Marrying physical security with computer security can help to strengthen an organisation's overall risk profile, but Kent Anderson, a member of the Certified Information Security Manager (CISM) board within the Information Systems Audit and Control Association (ISACA), argues that to be truly effective, we must beyond this and embrace the concept of enterprise risk management. How can this best be achieved, and what will the result look like? This article examines some of the drivers for this holistic form of risk management, and outlines some best practice principles to attain its goals. Today's security practitioners feel more pressure and accountability to perform, yet never seem to have the resources to get the job done. Consequently, “executives just don’t get it” is probably the most common explanation among frustrated professionals, but have we ever stopped to ask if maybe we’re the ones who don’t get it?