Do we really need a IT Risk Control Department?

In my experiences the difference between companies that have an effective risk control function and those that don’t is night and day. Businesses take risks, good businesses take measured risks. The same approach applies to the IT department.

A good risk controller needs to have the confidence of the business combined with complete respect from the IT department. In my view the risk control department should be the interface with external regulators and internal audit such that they retain a single voice amongst many opinions and neutralise the debate with the correct balance of risk.

The impact of a good risk controller is profound and I can highlight organisation A and B from my experiences (these are both real global blue chip organisations). You can guess which one had the effective risk control function:

Organisation A

  • Always a struggle to get business approval for changes even in times of significant emergency due to virus threats.
  • Information Security always played on the safe side and as a result security was incredibly tight, the environment was by result very hard to operate and harder to change.
  • Areas that had been audited had been ‘secured’ with firewalls were operationally left with no patching, virus protection or monitoring.
  • External regulators interfaced directly with Information Security and no brokering of solutions was considered to result in a more manageable environment.
  • One part of the company interrupted all business operations to apply a critical patch while another part on the same network in a different region did nothing.

Organisation B

  • Political differences between IT departments had historically hampered global change.
  • Identified risks were first attempted to be mitigated before being resolved by process first, technology second.
  • The expectations of global regulators and standards were influential at the start of a project not the end.
  • Projects were pushed through when needed and stopped in their tracks depending on business risk.
  • Share/Bookmark

1 comment to Do we really need an IT Risk Control Department?

  • David Lodge

    I think the question is less whether we need an IT Risk Control function, but what the function looks like and how it operates. Most companies I’ve seen operate a 3 line of defence model (Function, independent risk, and audit) but they work to different objectives.

    I am a risk controller by profession, and can see real benefit in controlling IT risk with a thorough understanding of the IT Function (CIO) and Business objectives. With these in mind, risk decisions can be taken with a real understanding of the implications such decisions will have on driving the business forward and the trade offs that must be considered. IT Risk is, afterall, Business risk.

    However, if IT Risk decisions are taken only considering a single IT risk factor (IT Security say) then the likely implication is that the IT function and business will be constrained in other ways.

Leave a Reply

 

 

 

You can use these HTML tags

<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

  • ct myelogram pacs system
  • wall bikes brooks saddles
  • breakfast seving tray
  • polish nail dryers
  • fleece henley pullover tops
  • use deepofix to filter mail
  • pattern split riding skirt
  • bearish etf mutual funds
  • hotel nassau inn wildwood
  • kenda executioner mud tires
  • logitech mice keyboard combo mx700
  • recipes for lamb ribs
  • purple floating candles
  • soccer referee delayed foul
  • home made leaf shredder
  • couples transformation retreat
  • victorian boot button bracelet
  • truck grills billet
  • emerald estate jewelry
  • free 3d moving screensavers
  • custom suits in washington dc
  • business briefcase river valley business report
  • troubleshooting eureka vacuum cleaners
  • ornamental iron fence designs
  • find a site for used mopeds
  • rent craps table austin
  • headstones pet memorial
  • cooking with viking pans
  • funky hip scarfs
  • ballet flats size 12
  • hugger mugger yoga products charcoal pilates
  • ingram marine towing
  • allsop metal art corner monitor stand
  • smoked sausage bean
  • ideas for christmas centerpieces
  • cat alarm clock animated video
  • getting skunk odor out of dog
  • 14 k bezel cz earrings
  • stained glass blocks for xmas
  • himalayan cats and kittens for sale
  • shock doctor braces mouth gaurd
  • 2004 simplicity cribs
  • aw table pads
  • fire prevention training material
  • holiday dresses under $70 cyber shop
  • chrome weld racing wheels
  • cheap massage couches
  • towle silver flutes replacement prices
  • mud lite xtr tire
  • autocad 2007 patches for windows vista
  • toyota camry bumper cover
  • heywood wakefield magazine tail table
  • change planes time miles flight airlines
  • resort quest kiawah island condo rental
  • 1983 31 airstream rv layout diagram
  • gameboy advance backyard hockey
  • plastic cutlery trays
  • four stroke evinrude outboard motors
  • fingernail fungal infection
  • retrospect backup
  • pooh fan pulls
  • unpopped popcorn christian company
  • mini van car covers
  • hydrogen cell powered cars
  • toastmaster parts
  • enviro corn stoves in pa
  • vintage toy airplanes funny flyers
  • bluefish fitness wear
  • boutique hotels in bangkok
  • celtic jewelry kelly va
  • tow bar mounted bike racks
  • leveraged inverse financial etf
  • custom nylon horse halters
  • how to clean popcorn maker
  • bath tubs corner jetted
  • tank scooter trunk
  • ideas for christmas stocking stuffers
  • satin pajamas petite
  • vera want napkin rings
  • outdoors umbrellas
  • mulia glass blocks
  • electric hand mixers
  • airsoft colt revolver
  • hotel churchill
  • motorcycle financing guide com
  • buy candy paint online
  • make your own chocolate covered apples
  • timeshares rentals for holidays
  • error code 2753
  • clear shield honda
  • rockport shoes ny listing
  • rack mount nrv10
  • diet after colon removal
  • ladies ballet slippers
  • hot gift recipe chocolate
  • us mortgage payoff calculator
  • electronic waste recycling
  • texas college fund 529
  • ceramic knives for sale
  • sedona arizonal hotels
  • ford money market account logon
  • gorham winfield stainless flatware
  • pet headstones in uk
  • rice chips
  • safe sea trouble
  • miss by elaine sissy
  • arizona fruta vida
  • designer melamine plates
  • education finance online shopping forex market
  • space based browser mmorpg
  • out door gym sets for kids
  • rims and wheels packages
  • comfortable shoes agent
  • 1000 detox foot patch
  • long straight blue 5-6 wig
  • unsecured motorcycle financing
  • new jersey automobile tires buy
  • hot plate cleaning methods
  • frozen margarita maker auction
  • rock bbq pits
  • professional eyelash glue
  • miken hal lite bats
  • microsoft wireless optical keyboard mouse desktop
  • scoreboard decor sports bedroom
  • composite super yachts
  • canadian advice for stock holders
  • discount schrade knives
  • electric stand mixers