Why Risk Management? Enterprise Risk Management has become a mandated business function involving the security of the entire organization. If you are tasked with designing an ERM you may be wondering “is my goal to determine if we are secure or if we can enable a more secure enterprise? Am I expected to engage business partners, provide meaningful metrics, to inform choices and decisions? Does the organization expect me to account for security responsibilities or am I the provider of a business service?"
… “yes”
This presentation is the largest body of work that we've committed to training. It takes 6 hours to deliver and involves quite a bit of discussion and activities. We hope you get some great ideas and encouragement.
Yes, if you are registered, you can have the PDF. This and all of our collateral will be made available to our clients and future clients in the EnterpriseGRC Reading Room.
Registration opens February First, 2022.
For now, we are sifting through several thousand pages of content to assure they are the most current and secure version of Adobe Acrobat. You'd be surprised what people can stuff in an old SWF or PDF, and you'd be sickened to find all the vulnerabilities on the endpoint of free marketing tools.
Aligning Enterprise Cyber & Security Risk Management - EnterpriseGRC Solutions Risk Management and GRC Support Solution
The content
- Proposed ERM Solution for Cybersecure Enterprises
- Agenda
- Why Risk Management?
- Minimizing material loss: Fraud, critical system failure, political damage, missed strategic milestones or significant loss of revenue.
- Ensures delivery of risk information to the business
- Enable business decisions via process for capturing, analyzing, mitigating and monitoring risks to the business
- Provide a unified management process for risk response
- Cyber Risk: What could go wrong?
- Reputation is a main target for cyber attacks
- Criminals value information – financial, health, critical infrastructure
- Cyber risk is challenging to understand and address
- Increased regulation over highly dispersed data
- Pace of technology change increases unknown dependency on third parties and shadow IT
- Capacity to trace our data making it harder to detect exfiltration
- The increased role of government and information custody results in enormous potential for financial sanctions
- Net Neutrality is no longer neutral
- Too Many Industries Mandates
- Why focus on the value of implementing Cybersecurity Oversight and Enterprise Risk Management
- Reduce operational expense through streamlined control structures
- Identifies cross-enterprise risks
- Aligns risk appetite and corporate strategy
- Enhance efficient risk response and rapid consistent decisions
- Seize opportunities to prevent the loss, rather than repair loss
- Align Process & Cybersecurity Tags to an Integrated Risk Approach
Risk Management goals include common security & information management practices found across enterprise management regulation and standards
- One Common Conceptual ERM Approach uses NIST Framework for Improving Critical Infrastructure Cybersecurity
- NIST CSF (Cyber Security Framework) provides a cyber security model
Like International CIS Critical Controls, other countries and the 28 member states of the EU, (such as United Kingdom and Australia), provide national cybersecurity strategy in the form of mandates, regulations and guidance.
- Another approach to ERM involves using Center for Internet Security’s Critical Security Controls – they are mapped!
- CIS – NIST CSF – FedRAMP /NIST 800-53 – ISO27002 – GDPR – PCI – SOC 2 Share Common Risk Control Requirements; Leverage Unified Approach
- Cybersecurity Governance & Committee Approach
- Success Factors – Cybersecurity & Governance Committee
- Methodology is simple and understood
- The approach is proven and tested
- Action plans are monitored and measured, using management processes already in place
- Governance approach is clear, endorsed by leadership, sustains continuous corporate interests.
- Governance & Risk Management program adapts to the organization’s culture
GRC Requires a Balanced Approach
- Phase I. Establish Enterprise Risk Management
Map to Security Risk & Compliance and Program Infrastructure - Risk Management Process - Purpose and Scope
- GRC via Facilitated Compliance Management (FCM)
- Cybersecurity Risk Oversight – Highs and Lows
- Initial program matures from spreadsheets to GRC Application – is not robust, depends on a few highly skilled individuals, checks the boxes but doesn’t really move the needle to affect a more secure organization
- Moderate Maturity small to mid-size enterprise – outsourced ERM, up to 3 yearly audit events, can leverage a reporting product but isn’t heavily integrated to cybersecurity channels and enterprise security architecture
- Moderate to High Maturity: Enterprise GRC application sources from Legal, Corporate, and InfoSec, dedicated staff, supplies 4 or more audit types, Integrated GRC channels reflects the full Security Architecture, Continuous Monitoring, Risk-Based Automated Controls.
Corporate Risk
- External Risks – Global and Economy
- Cost Risks
- Schedule Risks
- Cyber & Technology Risks
- Operational Risks
- Legal and Regulatory Risks
- Market Risks
- Project Risk (Cost)
- Cost Risks: directly or indirectly under the project manager's control or within his or her area of influence
- Cost overruns by project teams or subcontractors, vendors, and consultants
- Scope creep, expansion, and change that has not been managed
- Poor estimating or errors that result in unforeseen costs
- Overrun of budget and schedule
- Schedule Risks: can cause project failure by missing or delaying a market opportunity for a product or service.
- Inaccurate estimating, resulting in errors
- Increased effort to solve technical, operational, and external problems
- Resource shortfalls, including staffing delays, insufficient resources, and unrealistic expectations of assigned resources
- Unplanned resource assignment--loss of staff to other, higher priority projects
- Enterprise Risk Management Channels

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics