Trend 19: Security Strategy, Risk Strategy Become Integrated

The need for a unified strategy will grow more urgent. From a corporate risk management perspective, IT security is not just for keeping viruses, hackers and crooks at bay; it's also critical in order to stay compliant with regulations, avoid litigation and indictment, and prevent escalating insurance premiums.

But if IT security isn't integrated into an enterprise risk management strategy, CIOs and CSOs are less likely to consider the entire risk picture when they develop an IT security strategy. As a result, fundamental questions such as how much risk is acceptable are being overlooked. Integrating security and risk strategy won't take place overnight—it's too big a shift in how security is understood for that to happen, and requires a change not just in security policy but in security governance—but it will take place over time.

Trend 19


See all 30 Trends




Comment on this article
Comment Now  |  So what can you do about it? by davidlsharpe, 5/15/2007 8:08:49 PM

Keep your Windows machines patched and keep your antivirus up to date. For Symantec enterprise customers, the process of upgrading those out-of-support SAVCE agents (7.x and 8.x) got simpler. There is an article available at www.sharpebusinesssolutions.com/savce_upgrade.htm describing the process.

Read More ###  |  Reply to this Comment  |  Report Abuse

Internal security by veronicam, 2/9/2007 1:49:50 PM

Of course it is important to be compliant but I think a lot of people also view security as a precaution that must be taken for external threats when internal threats are just as harmful to a business as any other.

Take this quiz to learn more about internal threats:
http://www.iwantmyess.com/?p=162


Read More ###  |  Reply to this Comment  |  Report Abuse

Upcoming eSeminars

Data Protection Virtual Tradeshow
Cameron Crotty 50x50

Available On-Demand
Join Cameron Crotty and experts as they explore best practices and solutions needed to maintain a secure flow of data.
Available On-Demand
Security 2.0: Controlling Complexity
with Cameron Crotty. Sponsored by Symantec
Available On-Demand
Backup Exec 11d - The Gold Standard in Windows Data Recovery
with Frank Derfler. Sponsored by Symantec
Advertisement