Data Risk Governance

Exploring the intersection between information security, privacy, technology and the law.

Archive for April, 2010

Failed Risk-Based Security: Notes from Donn Parker RSA 2010 Presentation

Posted by Matt on April 22, 2010

Failed Risk-Based Security

Posted in 19004365, Information Security, Risk Assessment, Risk Management & Compliance | Leave a Comment »

Helping Lawyers Overcome Cloud Anxiety

Posted by Matt on April 22, 2010

Author and attorney Julie Tower-Pierce contributed  short little article to the April 2010 issue of Information Security magazine, that encourages IT personnel to provide insight and clarity on cloud computing to corporate counsel. Corporate counsel are rightly concerned about a variety of data protection risks  stemming from the use of third-party computing services.  Tower-Pierce writes, “By using straightforward, practical explanations and real-world analogies/examples, minus excessive technicalities when possible, you can impart a firm understanding of the mechanics of cloud computing and help lawyers gain perspective.”

I have no qualms about this approach whatsoever. The challenge is getting the two sides to even have the conversation. Most likely, the conversation would originate during the a company’s vendor (third-party) assessment process. This is the most frequent interaction between in-house counsel and information security or other risk assessors. The contractual relationship is often hammered out simultaneously with the IT controls assessment.

Another opportune time to have the conversation is during a corporate risk committee or IT governance steering committee meeting. These meetings take on a variety of shapes, names and participants, but whatever the risk management authority looks like, it should incorporate discussions on emerging topics such as cloud computing.

A third opportunity to have such discussions would be to invite legal to participate in the development of a cloud computing security policy,  a part of a firm’s overall information security policy framework.

Posted in Controls, Information Security, Risk Assessment | Leave a Comment »

ISO 31000

Posted by Matt on April 12, 2010

Here’s a link to a short article describing the new ISO 31000:2009 standard, purportedly a generic risk management process guide that is industry agnostic.

Posted in Risk Management & Compliance, Standards & Frameworks | Leave a Comment »

 
Follow

Get every new post delivered to your Inbox.