Rev2 IT Information SecurityRisk ManagementFebruary 26, 2010
Today’s DiscussionAgendaRev2 IntroductionRiskView FrameworkExamplesNext StepsGoalsIntroduce RiskViewTMa decision support system which helps identify and focus on business-material risksUnderstand your risk-management focus areas & processes2
Rev2 Risk ManagementInfoSec RiskSupply Chain RiskService Delivery RiskRiskView replaces ad-hoc processes with aFact-based, Scalable, Repeatable FrameworkIdentify under controlled risk via business viewsFocus on the most material drivers“What-if” controls testing
ButBig ExposurePlenty of DataInfo sec tools and services regularly identify 100,000’s vulnerabilitiesTodayRiskView provides a fact-based, scalable, repeatable process4Most companies collect large vulnerability data sets, but face big material risk in information security. Because…Reactive response
Perception vs. facts
Wasted money
On-going vulnerabilityValue is limited by…Data silos
Inconsistent data
Wrong metrics
Changing process
Inadequate toolsHow do you prioritize 1 Million vulnerabilities?
StructureSystemsToolsInfo Sec Risk Mgt requires a formal strategy and organization approachAn on-going formal process is needed to meet  goals and execute strategySpecial tools are required to consistently and efficiently analyze large data setsKey Elements IncludeLeadership– To coordinate across business units
Metrics—Consistent metrics for materiality of business impact
Risks and Policies—To identify risks and define policies to limit exposure
Compliance—Regular evaluations to learn policy compliance and violations
Risk Updates—Regular reviews for materiality score changes
Measures and Actions—Regular risk assessments with next steps to fix key findings

Risk View Info Sec Intro 3.4.10