CISO Perspective - Evaluating and Communicating Information Risk.

Russ Pierce, Phil Venables, Kavitha Venkita, Eric Johnson · WEIS · 2008

While security professionals have long talked about risk, moving an organization from a “security” mindset to one that thoughtfully considers information risk is a challenge. Managing information risk means building risk analysis into every business decision. In this panel, we will discuss how CISOs are working to move the conversation from security towards information risk. In particular, we will address questions about risk categorization, communication, and measurement such as:

Read the paper · More papers on PaperTik