Risk
6/26/2008
07:40 PM
George V. Hulme
George V. Hulme
Commentary
50%
50%

Catalyst Conference 2008: GRC Is A Four Letter Word

If you work anywhere near the risk management functions within your company, whether it be as an executive, manager, auditor, or IT security practitioner, you've probably heard from many vendors trying to sell you a "GRC solution." Burton Group analysts say you just may be better off covering your ears.

If you work anywhere near the risk management functions within your company, whether it be as an executive, manager, auditor, or IT security practitioner, you've probably heard from many vendors trying to sell you a "GRC solution." Burton Group analysts say you just may be better off covering your ears.During a presentation today at Burton Group's Catalyst Conference 2008, Bob Blakley, VP and research director at Burton Group, said that the primary goal of any governance program should be "round-trip" management, meaning a continuous feedback loop between the business and management. And while G(overnance), R(isk management), and C(ompliance) are each important organizational categories, Blakley said, they are not an IT product market or a solution.

If Blakley is right, and I believe to a large extent he is, then that would make it challenging for vendors such as BWise, CA, and Oracle to make inroads with their GRC applications. These applications aim collect data throughout an organization, and help them to be able to monitor how well risk is being managed, whether that be IT security risks, regulatory compliance risks, or other sorts of business risk, such as that from natural disasters, and how well the business continuity and disaster recovery plans have the company prepared.

However, Blakley argued that governance, risk management, and compliance, as a whole, can't be automated -- that these are fundamentally human responsibilities and tasks, tools that can be used to automate certain tasks within the separate GRC functions, and that they should be maintained -- and thought about -- as individual silos.

There are many tools that help organizations manage and automate IT security related risks, from identity and provisioning management to vulnerability scanners and patch managers, and it's also gotten easier to attain the data from those security tools, application logs, provisioning reports, and financial systems to better manage all aspects of regulatory compliance and audit survival.

However, there's not been the same headway in the governance part of GRC. Here's how Blakley defined what needs to be done to achieve proper governance:

  • Define organizational risk appetite
  • Define corporate policy
  • Assign responsibilities to specific people
  • Review regular risk management reports
  • Measure risk managers on value creation
  • Define organizational compliance targets
  • Review variance and time-to-remediate reports
  • Measure compliance officers on time-to-remediate and compliance effectiveness

While some of these governance activities could be reduced down to a dashboard view, by the time the data and metrics for both regulatory compliance and IT security are pushed up to the executive level, so much detail will have been lost the report would be meaningless.

I also agree with Blakley that GRC should not be used as a "catch-all" term. Security, compliance managers, and business leaders need to say exactly what they mean: governance, risk, or compliance when discussing risk management. And you need to make sure you force your vendors to do the same.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-4467
Published: 2015-01-30
WebKit, as used in Apple iOS before 8.1.3, does not properly determine scrollbar boundaries during the rendering of FRAME elements, which allows remote attackers to spoof the UI via a crafted web site.

CVE-2014-4476
Published: 2015-01-30
WebKit, as used in Apple iOS before 8.1.3; Apple Safari before 6.2.3, 7.x before 7.1.3, and 8.x before 8.0.3; and Apple TV before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulner...

CVE-2014-4477
Published: 2015-01-30
WebKit, as used in Apple iOS before 8.1.3; Apple Safari before 6.2.3, 7.x before 7.1.3, and 8.x before 8.0.3; and Apple TV before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulner...

CVE-2014-4479
Published: 2015-01-30
WebKit, as used in Apple iOS before 8.1.3; Apple Safari before 6.2.3, 7.x before 7.1.3, and 8.x before 8.0.3; and Apple TV before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulner...

CVE-2014-4480
Published: 2015-01-30
Directory traversal vulnerability in afc in AppleFileConduit in Apple iOS before 8.1.3 and Apple TV before 7.0.3 allows attackers to access unintended filesystem locations by creating a symlink.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
If you’re a security professional, you’ve probably been asked many questions about the December attack on Sony. On Jan. 21 at 1pm eastern, you can join a special, one-hour Dark Reading Radio discussion devoted to the Sony hack and the issues that may arise from it.