Information Security And Risk Management: Program Structure And Value Add

This discussion will follow this agenda:1.What is risk analysis and what is it supposed to do?2.What does it tell you and what does it not tell you?4.Why are there so many seemingly different “frameworks?5.Is one better than another?6.Implementation of Risk Management as a “cultural” aspect in the org

Basic Level Code: GRC0000176
Speaker
By Internal Team In General
Share:

  • The Essence of Risk Analysis and Risk Management
     o Examples of Risk Management Frameworks
           - NIST RMF
           - FAIR
           - ISACA IT Risk
     o  Similarities and Differences
     o  How to evaluate, how to choose
     o  Program Development:  Evolution, not Revolution
     o  Remediation Strategy:  making informed mitigation choices
  • The Risk Analysis Process and its greater business value

  • CISO
  • CPO
  • Legal Counsel
  • IT Mgmt
  • Operations officers
  • Compliance Officers
  • Privacy Officer
  • Security Officers.