Most Popular Stories
- 3 ways for CIOs to become business leaders
- Chrome 17's new features enhance speed, security
- FBI insists cloud providers meet strict security requirements
- Multiple monitors makes some multitasking faster, easier
- Bug in Trendnet webcams exposes them to public viewing
- Spotlight: Intel launches 520 Series solid-state drive
Events
- CIO Healthcare Summit
March 11-14 — Scottsdale, AZ - The AIIM Conference 2012
March 20-22, 2012 — San Francisco, CA - Ready to meet the next-generation of business?
March 4-6 2012 — San Francisco, CA - The AIIM Conference 2012
March 20-22, 2012 — San Francisco, CA
Sponsored Links
Free Newsletter
HOT TOPICS >> Tech world's top flops and fiascos of 2011 | Windows 8 slideshow | Cybersecurity | Caron's Q&As
INDUSTRY >> Healthcare IT | Government IT | Financial Services IT | Biotech IT | Compliance IT
Free Newsletter
FierceCIO provides CIOs with IT best practices, business intelligence, and forward-looking IT strategies. Join 32,000+ industry insiders who get FierceCIO twice a week via email and save time.
About | View Sample | Privacy
Latest News
Popular Topics
Whitepapers
- Whitepaper: Integrated Analytics and WCM Can Improve Performance & ROI
- Penetration Testing with Metasploit Framework
- Because Hope Is Not A Strategy: Business Continuity/Disaster Recovery Planning
- The Shortcut Guide to Secure, Managed File Transfer
- Enterprise Digital Assistant Leverage in the Emerging Mobile Enterprise
- Demystifying The Android Malware
Policy: The first step toward risk management
When it comes to dealing with risk management issues, think policy first and technology second. Build a defensible case. Once you have a policy in place, technology--in the areas of Identity and Access Management (IAM), Security Information and Event Management (SEIM), configuration auditing, content monitoring, database activity monitoring and IT governance risk/compliance--can help. If you implement only one technology, it should be IAM, with SIEM running a close second. But they are no substitute for solid policy. Configuration management systems can help find faulty business practices, but it's policy that makes users understand what's acceptable usage and what isn't. Configuration auditing technology pinpoints unauthorized changes in the network, but you still need well-defined configuration policies and change management processes. Database activity monitoring technologies are a good idea, but it's not enough; systems must be re-engineered for encryption. IT governance and policy management technology can help businesses strengthen external audit posture and can reduce the cost of control measurement and compliance reporting, but it shouldn't be considered a substitute for policy development work.
Learn more about the importance of policy in risk management:
- read the article at SearchCIO
ALSO: read this on the intersection of risk and compliance
Related Stories
- Risk management: Growing pains
- Open-source can be risky business
- Merging physical security and IT security
- Issues to ponder in security outsourcing
- The Foley scandal and IM data trails
- Attorney General: ISPs must retain data
- How to foster CIO/CSO collaboration
- Lessons learned from an internal hack event
- Voter database lacking security controls
- Making security legally defensible
Home
| Subscribe | Advertise | RSS |
Privacy
| Site Map
| EditorsTHE FIERCEMARKETS NETWORKFierceEnergy | FierceSmartGrid | FierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceHealthPayer | FiercePracticeManagement | FierceEMR | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceGovernment | FierceHomelandSecurity | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceMedicalDevices | FierceDrugDelivery | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceEnterpriseCommunications | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2011 FierceMarkets. All rights reserved. |
![]() |




