Data Risk Governance

Exploring the intersection between information security, privacy, technology and the law.

Risk Management

The great debate on Risk Assessment (under development).

The Problem With Risk-Based Security, And How To Fix It, (Notes from RSA Conference Presentation by Donn Parker)

I’ve added a sample risk assessment that was conducted to help inform a decision on whether or not to encrypt internal network traffic. While the risk assessment is specific to one company in the financial sector, the underlying risk model is broadly applicable and can be modified to suit a variety of needs.

Analysis & Review of FFIEC Multi-Factor Authentication Guidance

A Sample Multi-Factor Authentication Risk Assessment

Guidance for Executives, CEOs and Directors

Book Review: The Failure of Risk Management, Douglas W. Hubbard

Book Review: IT Risk Management In Enterprise Environments

Book Review: IT Risk Management

Risk IT – An IT Risk Management Framework from ISACA

Segregation of Duties

2 Responses to “Risk Management”

  1. J Barker said

    The link to a “sample risk assessment” is broken on following page
    http://datariskgovernance.com/risk-assessment/

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Connecting to %s

 
Follow

Get every new post delivered to your Inbox.