Pages

Showing posts with label GRC. Show all posts
Showing posts with label GRC. Show all posts

Saturday, February 21, 2009

Proactive and Reactive approach to Risk


Proactive and reactive approach to Risk ….

Everybody is joining the bandwagon of ITGRC or GRC, if you are database Security Company or networking Product Company, all of them have their messaging around compliance. Compliance is small piece of the big picture, in my opinion big picture is RISK which drives G and C.
Risk is what we want to manage and will decide our survival. I may be all compliant, and still have lot of Risk unaddressed or at unacceptable level.
Risk is relatively new concept to IT and CISO/CIO has started understanding this concept but still we are light years behind financial risk managers who has very good understanding of risk and its different models (don’t look at financial stocks right now to prove me wrong ;) !!! )
I am sure you get the point, when financial industry has been using risk since last 100 odd years versus IT has started using risk in last 5 years or may be decade before.
Just like controls risk identification can be proactive or reactive in nature. This is not a debate about which one is better, we need both. By very nature of risk assessment, it is future prediction based on certain parameters which is nothing but “Perceived Risk”. Other is your reactive approach to risk which is backed by hard to refute numbers, for example Anti Virus incidents in last 1 year or emergency change management which can be directly correlated to Network Downtime. Based on these numbers you can associate new risk or change the existing risk and controls mitigating the risk. This is very powerful autonomous system. Perceive Risk is nothing but what you are afraid of and reactive approach will be what you should afraid of !!! This self correcting system will improve over time and will self adjust it self, its not perfect but its very powerful and effective. There is always systemic risk ! Anyone in wall street today knows about this risk , there is always a risk of system failure and no one is saved from that, since you are part of the system unless you change or create your own system, then you have some control over system risk. Like any thing in life this system is also not flawless and has its own risk, but this approach is defnintely better than just risk identification and assessment in board room for few hours.

Question is how to get the reactive risk numbers? Its simple, most of the organization has Security and networking product implemented. Only required thing is product to collect the numbers from these silo solution and provide the trending. Based on trends and threshold one can definitely identify what you should be worried about, again in financial world these people have been doing this for years with VIX index, S&p 500 , Unemployment numbers and so on, some of them are leading indicators of things to come or some of them are lagging indicators .

Apply same concept to IT and you will get similar indices for your environment, which is true only for your environment and business, since business objective for every company is different their risk appetite will obviously be different.

Risk is such a fascinating topic, which involves, imaginations, math( discrete probability in math class remember ? ), Business and strategy !! Haven’t seen any topic covering so much of depth and breath.
Proactive and reactive is just the nomenclature assuming you are identifying risk after something has happened versus you identifying the risk before something !
However continuing from my first blog, business has all the rights to take their chances and accept the risk in order to achieve their business goals as long as Risk is acceptable. Million dollar question is who will decide what is acceptable? And what is acceptable risk ? May be good topic for my next blog….till then ….Keep watching DOW ;) Risk may reduce and then its time to buy :)

Wednesday, August 22, 2007

Is fully Compliant = Good Security ?

Buzz word IT-GRC , who doesn't know about it !! 17 billion dollar market as per Gartner report.
You must be wondering what is this GRC acronym stands for ? why people are talking about it ?

I would like to take this opportunity and dwell a bit in to IT-GRC and express my thoughts on this market. Let me answer the question what GRC is , G stands for Governance, R stands for Risk and C stands for Compliance, as easy as it sounds...well not really !:).

Why people are talking about GRC ? Simple because Government and Compliance industry combination have created havoc for institution specially for finance and medical insurance companies in US. Regulations like SOX, HIPAA, GLBA, FFIEC BASELII ,PCI and what not !!! Every country has its own standards, Europe will have its own version of SOX and HIPAA . To comply to this regulation smart marketing people came up with Frameworks, Initially BS-7799 now ISO -27001, COBIT and now I am hearing ITIL , all claiming to be master framework which can manage other frameworks regulation and standards. Each framework has its certification from which they create revenue.

All the regulation and standards has one thing in common , Due care/Due diligence, Which means there is sufficient effort to prevent something catastrophic from happening and if fatal event happenes then organization is ready for the same. Also it takes in to account that Risk to the business is known and either it is accepted or mitigated or transferred.

However , these giant frameworks and strict regulations are good to have but as they say "Everything in Excess is Poison". Too many regulations and too many framework will create chaos for the management and last but not least too many threats and vulnerability and hence too many RISK. Hence there is a need for GRC which can manage these many compliance to regulations.

If we see current scenario, compliance is merely a tick mark against the requirement. Do You have IDS? Yes ...complied ! woohoo ... Well if Auditor is good he might get in to the details of log management , sometimes they do but at the end of the day BufferOverflow in .dll sounds like latin to Auditor. He will see a process, is this bufferoverflow mitigated?, and my worry is most of compliance auditors doesn't have the expertise to question the mitigation efficacy !

Million dollar question if I am completely compliant to say PCI regulation does it mean that I am secure ? More often than not , answer is no. original scope of regulation is to strengthen security but the results are totally opposite !! In the burden of so many regulations, security takes the backseat ! Multiple issues, Internal security guys are loaded with too many regulations, External auditor can not be expert in all the areas, and if you go to Defcon you will realize that no matter what you do , you are always hackable ! so why create strict regulation to compliance , its better to provide some leeway to the companies in midst of so many regulations.

We have seen so many hacking incidence in the past , TJ MAX, and similar and Monster being the recent.

We will continue to be like Ostrich and will be happy looking at all the compliance reports and sending them to management to make them happy but at the end of the day it takes single Security breach to break that myth.

Finally you are as good as your people. You make sure that people has required ethical and technical skills and you should be good ! No compliance standard or regulation can beat the security that you get from your loyal employees !