<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Is IT Governance, Risk and Compliance Management Greek to You? in Enterprise Security Trends Blog | HP Blogs</title>
    <link>http://h30507.www3.hp.com/t5/Enterprise-Security-Trends-Blog/Is-IT-Governance-Risk-and-Compliance-Management-Greek-to-You/ba-p/103375</link>
    <description>&lt;p&gt;&lt;font color="#000000"&gt;&lt;font size="3"&gt;So what is Government Risk Compliance (GRC)? There is much confusion when it comes to GRC and you may be saying “it’s all GReeC to me” (excuse the topical pun). Let me explain briefly.&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font color="#000000" size="3"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;font color="#000000"&gt;&lt;font size="3"&gt;G = Governance&lt;/font&gt;&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;font color="#000000" size="3"&gt; &lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;font color="#000000"&gt;&lt;font size="3"&gt;Governance, which is an over-used term, is nonetheless essential for ensuring that what is most important to us is actually protected appropriately through strong processes and oversight by accountable senior stakeholders.&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font color="#000000" size="3"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;font color="#000000"&gt;&lt;font size="3"&gt;R = Risk (Management)&lt;/font&gt;&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;font color="#000000" size="3"&gt; &lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;font color="#000000" size="3"&gt;All companies face &lt;/font&gt;&lt;a href="http://www8.hp.com/us/en/solutions/solutions-detail.html?compURI=tcm:245-339290&amp;amp;pageTitle=enterprise-security&amp;amp;contentView=business" target="_blank"&gt;&lt;font color="#0000ff" size="3"&gt;enterprise security&lt;/font&gt;&lt;/a&gt;&lt;font size="3"&gt;&lt;font color="#000000"&gt; risks. Sometimes these are physical risks like the possibility of a burst pipe in your data center, but most security risks involve your critical information. Risk management is not about eliminating all risks but addressing those which you consider to be unacceptable to your organisation in its current state and context.&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font color="#000000" size="3"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;font size="3"&gt;&lt;font color="#000000"&gt;C = Compliance&lt;/font&gt;&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;font color="#000000" size="3"&gt; &lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="3"&gt;&lt;font color="#000000"&gt;Compliance may sound like the least exciting of these and seem to be a passive activity – literally, to comply, in everyday English, is to “go along with” someone else’s “rules” or expectations. We all know that being reactive however, i.e. not being in the driving seat, can be expensive and exhausting, especially in the context of much regulation. So, in my opinion, compliance is an unfortunate term and should be considered in much more of a proactive, holistic light.&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font color="#000000" size="3"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;font size="3"&gt;&lt;font color="#000000"&gt;3 Parts of Governance, Risk and Complaince&lt;/font&gt;&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;font color="#000000" size="3"&gt; &lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="3"&gt;&lt;font color="#000000"&gt;The 3 facets of GRC do give more of a rounded approach and ideally should be considered together as they are interlinked, e.g. good risk management can help in achieving compliance through providing focus.&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font color="#000000" size="3"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="3"&gt;&lt;font color="#000000"&gt;Good GRC consultants will help you consider your organisation’s aspirations and maturity with respect to security. To use a school analogy, achieving full marks in a test does not mean the questions have been fully understood or were even the right questions for you. &lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font color="#000000" size="3"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="3"&gt;&lt;font color="#000000"&gt;To avoid repeatedly being required to “score an A grade on each test” by yet another “independent auditor,” experienced GRC consultants should be able to help you:&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font color="#000000" size="3"&gt; &lt;/font&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;font color="#000000"&gt;&lt;font size="3"&gt;Understand and plan for regulatory compliance appropriate to your organisation’s sector, maturity and size – ideally taking a matrix approach, i.e. avoiding addressing each regulation/standard in isolation (considerable money can be saved by eliminating compliance overlap)&lt;/font&gt;&lt;/font&gt;&lt;/li&gt;&lt;li&gt;&lt;font color="#000000"&gt;&lt;font size="3"&gt;Formulate a risk management approach that is appropriate to your organisation’s size and culture, i.e. as simple and understandable as possible, yet includes risk ownership and some accountability&lt;/font&gt;&lt;/font&gt;&lt;/li&gt;&lt;li&gt;&lt;font color="#000000" size="3"&gt;Consider information governance, i.e. understand and monitor where your critical information is (this is particularly pertinent if &lt;/font&gt;&lt;a href="http://www8.hp.com/us/en/solutions/solutions-detail.html?compURI=tcm:245-300983&amp;amp;pageTitle=cloud-computing&amp;amp;contentView=business" target="_blank"&gt;&lt;font color="#0000ff" size="3"&gt;cloud computing&lt;/font&gt;&lt;/a&gt;&lt;font size="3"&gt;&lt;font color="#000000"&gt; services are being considered and/or you are subject to powerful legislation such as the US Patriot Act)&lt;/font&gt;&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;font color="#000000"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;font size="3"&gt;&lt;font color="#000000"&gt;Some Additional IT Risk Management Tips&lt;/font&gt;&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;font color="#000000" size="3"&gt; &lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="3"&gt;&lt;font color="#000000"&gt;Activities that should incrementally improve your organisation’s security posture and can help compliance demonstrations become less and less painful are suggested below:&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font color="#000000" size="3"&gt; &lt;/font&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;font color="#000000"&gt;&lt;font size="3"&gt;Consider certification against a well-respected information security standard, e.g. ISO27000 – this can take rather a long time but even the journey itself can go a long way to show compliance with some/all of most other standards/regulations &lt;/font&gt;&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt; &lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;font color="#000000"&gt;&lt;font size="3"&gt;If the above is not feasible for you, consider the rest of the tips below:&lt;/font&gt;&lt;/font&gt;&lt;ul&gt;&lt;li&gt;&lt;font color="#000000"&gt;&lt;font size="3"&gt;Persuade the bosses of the importance of the business’s information and the benefits of proactive protection, rather than firefighting later&lt;/font&gt;&lt;/font&gt;&lt;/li&gt;&lt;li&gt;&lt;font color="#000000"&gt;&lt;font size="3"&gt;Assess what policies you have, especially for incident management – should be easily accessible and brief (with fuller versions available if required)&lt;/font&gt;&lt;/font&gt;&lt;/li&gt;&lt;li&gt;&lt;font color="#000000"&gt;&lt;font size="3"&gt;Consider where automation is feasible, e.g. aspects of data centre automation&lt;/font&gt;&lt;/font&gt;&lt;/li&gt;&lt;li&gt;&lt;font color="#000000"&gt;&lt;font size="3"&gt;Identify and equip an individual or team to monitor vulnerabilities and threats&lt;/font&gt;&lt;/font&gt;&lt;/li&gt;&lt;li&gt;&lt;font color="#000000"&gt;&lt;font size="3"&gt;Consider how and what you monitor plus how you can improve your capability to examine event histories&lt;/font&gt;&lt;/font&gt;&lt;/li&gt;&lt;li&gt;&lt;font color="#000000"&gt;&lt;font size="3"&gt;Provide some basic training for all personnel in security awareness&lt;/font&gt;&lt;/font&gt;&lt;/li&gt;&lt;li&gt;&lt;font color="#000000"&gt;&lt;font size="3"&gt;Ensure that senior management are regularly updated, in an appropriate way (i.e. in business terms), about changes in the organisation’s risks, so that they see this as being aligned with and relevant to the real business   &lt;/font&gt;&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;font color="#000000" size="3"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="3"&gt;&lt;font color="#000000"&gt;This list is not exhaustive but is an indication of what is widely accepted as good and reasonable practice - which is what a good compliance auditor should really be looking for, in my opinion.&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font color="#000000" size="3"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="3"&gt;&lt;font color="#000000"&gt;What have your experiences been with Governance, Risk and Compliance? Do you have any additional tips to add?&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font color="#000000" size="3"&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;For more information, you can download HP’s &lt;a href="http://h20195.www2.hp.com/V2/GetPDF.aspx/4AA3-5510ENW.pdf" target="_blank"&gt;&lt;font color="#0000ff"&gt;Governance, Risk, and Compliance Consulting and Project Services&lt;/font&gt;&lt;/a&gt; capability fact sheet.&lt;/p&gt;</description>
    <pubDate>Fri, 02 Dec 2011 15:01:02 GMT</pubDate>
    <dc:creator>NeilPass</dc:creator>
    <dc:date>2011-12-02T15:01:02Z</dc:date>
    <item>
      <title>Is IT Governance, Risk and Compliance Management Greek to You?</title>
      <link>http://h30507.www3.hp.com/t5/Enterprise-Security-Trends-Blog/Is-IT-Governance-Risk-and-Compliance-Management-Greek-to-You/ba-p/103375</link>
      <description>&lt;p&gt;&lt;strong&gt;&lt;font color="#000000"&gt;If GRC is Greek to you, you’re not alone. But it doesn’t have to be complicated. Check out these tips and steps to help simplify Governance, Risk and Compliance Management starting with an easy definition.&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;</description>
      <pubDate>Fri, 02 Dec 2011 15:01:02 GMT</pubDate>
      <guid>http://h30507.www3.hp.com/t5/Enterprise-Security-Trends-Blog/Is-IT-Governance-Risk-and-Compliance-Management-Greek-to-You/ba-p/103375</guid>
      <dc:creator>NeilPass</dc:creator>
      <dc:date>2011-12-02T15:01:02Z</dc:date>
    </item>
    <item>
      <title>Re: Is IT Governance, Risk and Compliance Management Greek to You?</title>
      <link>http://h30507.www3.hp.com/t5/Enterprise-Security-Trends-Blog/Is-IT-Governance-Risk-and-Compliance-Management-Greek-to-You/bc-p/115679#M61</link>
      <description>&lt;p&gt;Nice read on GRC.&lt;/p&gt;</description>
      <pubDate>Tue, 12 Jun 2012 00:51:18 GMT</pubDate>
      <guid>http://h30507.www3.hp.com/t5/Enterprise-Security-Trends-Blog/Is-IT-Governance-Risk-and-Compliance-Management-Greek-to-You/bc-p/115679#M61</guid>
      <dc:creator>Bob Jones</dc:creator>
      <dc:date>2012-06-12T00:51:18Z</dc:date>
    </item>
  </channel>
</rss>

