Home > CIO News > Risk management staffing isn't always part of IT
CIO News:
EMAIL THIS

Risk management staffing isn't always part of IT

By Matt Bolch, Contributor
07 Jun 2007 | SearchCIO.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Does your risk management plan include staff requirements solely from within your current IT group? If so, you should consider looking outside your IT organization for other qualified individuals to tackle your risk management plan.

More on risk, staffing
Risk Management Resource Center

Staffing Resource Center
"It's a common mistake that companies make to think an IT risk management organization can be staffed by folks with industry certifications around security," said Ed Adams, CEO at Security Innovation Inc., a Wilmington, Mass.-based independent application security firm. "In order to understand the ramifications of one or a series of events, one has to understand the business and the events in terms of potential lost revenue."

And while understanding what occurred may require some technical acumen, Adams said, one needs business know-how to interpret the outcome. An ideal risk manager should have an undergraduate degree in computer science and a master's degree in business administration to effectively manage a company's risk management plan.

"IT shouldn't make risk decisions," added Paul Davis, who works at Blue Bell, Pa.-based Unisys Corp. as vice president and program manager for enterprise security, global outsourcing and infrastructure services. "IT is there to deliver services to the business, while assessing risk requires a certain due diligence that's strategically focused on the business."

A company's risk management department should work in conjunction with IT on projects as early as possible to identify potential pitfalls every step of the way, which includes the architectural, engineering, implementation, operation and change or decommissioning phases.

People in those jobs need to be good communicators, technically savvy in multiple areas, business-sensitive, experienced in IT operations, focused on business security, and they should enjoy sleuthing and thrive on long hours, he notes. "It's a fascinating, brilliant job sometimes, but it can be quite boring," Davis said.

Planning for risk can be proactive or reactive, he added, but there should be a discipline around either approach. In his experience, risk assessors commonly work in a security office, rather than in IT, and the department reports to the CIO, director of IT, CFO or some other C-level executive.

Meanwhile, many companies in the financial services sector often augment risk management teams with a unit that handles IT-related assets such as the network, databases, laptops and critical applications.

Steve Suther said he sees chief risk officers (CROs) and those with similar titles emerging to become head of risk management. Suther helped establish the risk management program around compliance at New York-based American Express Co., where he worked for more than a decade before moving to Getronics, where he's senior information risk strategist.

The CRO may report to the CIO, "but more often they are peers," Suther said. "The risk management activity can't happen in the IT silo anymore. It has to happen on the business side and be conducted by people who speak business, understand business processes and can even help map them."

In smaller companies, risk management reporting should happen outside the IT function, Davis said. Employees who are implementing various technologies might not have the proper knowledge around security, regulatory compliance and company policies, so it's vital that risk assessors be independent.

Adams compares the relationship among IT, risk management and the company at large to the three branches of government, each providing checks and balances against the other two.

"Where the risk management organization rolls up within the overall company is critical," Adams said. "A CRO or CSO should be on par with the CIO and CFO. If not, it's like the judiciary is missing."

Matt Bolch is a freelance writer based out of Atlanta.

Tags: Strategy: Take stock of your risksIT staff development and retentionEnterprise information security managementEnterprise risk managementVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Strategy: Take stock of your risks
Enterprise risk management solutions for CIOs
Gartner: Future IT security jobs to focus on risk management strategy
Sustainability risk management: Beyond green IT
Outsourcing deals no good if contract is weak
Career advice for CIOs: Four qualities of a leader and more
'Millennials' buck IT security policies
Vetted IT negotiations reduce risk of project failure
Business process management: Avoiding the pitfalls
IT risk moves higher on security radar, report finds
IT security trends move toward information risk management

IT staff development and retention
IT staff retention likely to become an issue in economic recovery
Gen X, not Gen Y, leads adoption of social technologies in workplace
CIO management mistakes that can harm CIO careers, cause IT failures
Effective ITIL project leadership: Plan-Do-Check-Act
Swine flu -- not hurricanes -- leads disaster recovery agenda
Outsourcing IT jobs: Do U.S. companies and workers stand a chance?
Hit the ground running and make people your priority
Gartner: Future IT security jobs to focus on risk management strategy
Integrated business intelligence strategy spans app, BI developers
10 ways to keep your IT job in this recession

Enterprise information security management
Talking swine flu and Conficker with the CIO of the CDC
Network access control: Security advice for enterprise CIOs
Evaluating network access control: NAC policy enforcement matters
Enterprise risk management quiz for CIOs
Network access control now addresses multiple needs
Enterprise risk management solutions for CIOs
Gartner: Future IT security jobs to focus on risk management strategy
Avoiding gotchas of security tools and global data privacy laws
Security standards to help manage compliance for those federal funds
Information security and IT governance guides for CIOs

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
hard skills  (SearchCIO.com)
Internet addiction  (SearchCIO.com)
soft skills  (SearchCIO.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



CIO solution center has news, research, and guides to assist the unique challenges of the CIO
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2007 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts