Governance, Risk & Compliance Advisory Blog
Insights on best practices related to IT Audit & Compliance

Leveraging GRC for IT Security Measures

June 6, 2010 18:35 by nirav

Businesses are increasingly dependent on technology to automate processes in order to remain competitive and operate efficiently and effectively. However, these new opportunities create new risks and threats to the business. These risks not only originate from outside the organization, but also from within. According to the 2009 CSI/FBI Computer Crime and Security Survey, most reported security breaches are launched from trusted individuals hired by the organization.

A security breach to the organization's computer systems may cause:

  • Business disruption and denial of services
  • Leak of corporate and internal sensitive data
  • Exposure of private customer information
  • Legal repercussions due to regulatory non-compliance
  • Loss of goodwill

All stakeholders like partners, client, shareholders etc would require that information systems must have adequate internal controls and are effectively addressing security challenges. Needless to say, a security breach can be very embarrassing and costly. This is where an organization can leverage a well established GRC process to monitor security issues as well. GRC requires the organization to examine IT and operational processes, which gives management a roadmap of what's wrong and how to improve their company. However it is up to management to either take the risk or put into place appropriate processes and systems (including consulting, software and hardware to implement these systems) to manage the risks based on reasonable business decisions. Effectively the IT auditor can highlight where the company has stored value and highlight if the controls needed to protect those assets are deficient.


The first step is to recognize GRC as an asset and the IT audit organization as a friend of the company as a whole. Organizations should understand that GRC is a continuous process and not a onetime activity since risks are constantly evolving. The audit process is a constant process, not something that is done once a year. Also there is no pass or fail in GRC or an IT security audit. Organizations may also need to look at resources outside the company to test their security and consider the use of outside consultants to periodically check the strength of their systems and processes and also immediately remediate high risk areas where security measures are found wanting. Organizations also need to think in terms of investing in technology and also contact various vendors and consider the use of multiple firms to provide GRC services and products.


GRC also continuously educates users about threats and how they can be part of the solution, not the problem. The GRC process provides the knowledge necessary to build a more secure and risk aware/risk respondent company. "Assume the worst and hope for the best" are the best watchwords that are said of GRC. Risks may materialize any day, servers may get hacked, and employees may gain access to sensitive data and may get tempted to share company secrets looking for a quick buck. Organizations should not assume that the laws will protect their interest the important thing is to always keep auditing and testing.


Conclusion:
CEOs, CIOs sometimes see GRC as a strain on the bottom line and they fail to understand the implications of corporate risk and its consequences. For those organizations, GRC provides no benefits, only costs. To organizations that are able to see the long term survival of the organization as part of their business plan, GRC is a welcome framework to operate in a dynamic world where IT runs just about every aspect of their business and the nature of risks and threats are also ever-changing.
 


Be the first to rate this post

  • Currently 0/5 Stars.
  • 1
  • 2
  • 3
  • 4
  • 5
Tags: ,
Categories: General
Actions: E-mail | Permalink | Comments (39) | Comment RSSRSS comment feed

Related posts

Comments

June 14. 2010 02:13

Gravatar

This is why companies must regularly perform a SWOT analysis. By frequently analyzing the company's strenghts, weaknesses, opportunities and threats, the company will know where it's headed. For this reason, a SWOT analysis is also a great way to avert a crisis.

medical insurance

October 18. 2010 15:23

Gravatar

This site is cool! i visit here evaryday.

Cross cutting shredder

October 18. 2010 22:34

Gravatar

Where can i find your rss? I cant find it

14k white gold diamond smiley emoticon disk necklace 17

October 20. 2010 04:53

Gravatar

Its a pity you dont have a donate button, i would donate some =)

Compact refrigerator

October 22. 2010 20:34

Gravatar

Great site design!!!! Whattemplate did you use?

Kirsten Dunst (21) HD Wallpaper

October 27. 2010 00:34

Gravatar

It's true that business these days is much more complicated than it was in the past and in order to remain on the market and to have profit, one company must deal with many problems and find the best solutions. From your description, GRC seems to be a good solution. I also agree with what someone said before me. Marketing in very important these days, the marketing mix and the SWOT analysis are great ways to avert a crisis.

Videos

November 8. 2010 18:08

Gravatar

Its a pity you dont have a donate button, i would donate some =)

Why a poker bonus is offered

November 9. 2010 01:39

Gravatar

This site is great. i visit here evaryday.

Vanessa Minnillo (15) HD Wallpaper

November 9. 2010 23:27

Gravatar

This site is cool. i visit here evaryday.

Emo

November 10. 2010 23:56

Gravatar

Hey check out my blog too. I hope i have some interesting stuff too

Celebrity hairstyles and males

November 11. 2010 01:30

Gravatar

Great site design!!!! Whattheme did you use?

Panasonic lumix dmc zs7 12 1 mp digital camera with 12x optical image stabilized zoom and 3 0 inch lcd

November 11. 2010 02:19

Gravatar

Great site design!!!! Whattheme did you use?

Hello kitty light up usb optical usb mouse rare black

December 13. 2010 17:16

Gravatar

Interesting article, thanks for spending the time to assemble it. I like the direction you are taking your blog. I will be subscribing to your blog in order to follow alongdown the road. Looking forward to more posts soon.

Windows 7 Home Basic Activation Key

December 18. 2010 17:22

Gravatar

it's at all times an important expertise to read your weblog post many times

bad credit loans

January 6. 2011 04:31

Gravatar

Great site design!!!! Whattemplate did you use?

Exercise log

January 6. 2011 09:34

Gravatar

Thanks for posting this. i really had good time reading this.

Magics promise

January 6. 2011 10:17

Gravatar

I liked this article

Morning facebook statuses

January 17. 2011 13:09

Gravatar

Thanks,have a good time in diablo 2!

diablo 2 cd key

January 19. 2011 20:36

Gravatar

The fact that a lot of people fail to understand the implications of corporate risk and its consequences is worrying. Like you said, GRC will only provide costs...Maybe more articles like this one will help people get more informed. Keep up the good job! :-)

seo outsourcing

January 29. 2011 07:15

Gravatar

Thank you for another great weblog.In which else could I get this kind of tips composed in such an incite full way? I've a project that I am just now doing work on, and i am certain this will support me a lot..and I have been searching for such facts because from few days....Thanks!!!!!

Windows 7 Activation

February 8. 2011 10:18

Gravatar

I liked this article. It was so great.

How do i find a good college that offers a good music theatre and psychology program

February 13. 2011 19:50

Gravatar

Great post! indeed!

Trust facebook statuses

February 16. 2011 13:13

Gravatar

Great post! indeed!

Life facebook statuses

February 21. 2011 18:39

Gravatar

Great post! indeed!

God facebook statuses

February 22. 2011 10:26

Gravatar

I liked this article. It was so great.

Wizard of the grove

February 24. 2011 08:10

Gravatar

I liked this article. It was so great.

Dos and donts in online dating what you should and should not do with a girl online

March 9. 2011 15:09

Gravatar

I liked this article. It was so great.

Gus hansen high stakes poker online

March 21. 2011 10:47

Gravatar

Great post! indeed!

Santa Banta funny jokes

March 22. 2011 12:52

Gravatar

his is really awsome!! Thanks!!

Is blue mountain ski resort open

May 19. 2011 10:02

Gravatar

I think this article is very useful!Thanks for sharing it!

essay writing services

June 6. 2011 15:14

Gravatar

Plutôt d'ac avec ce qui est dit. J'espère travailler en Suisse. Cela fait un moment que j'y tiens. Excellent article.

Assurance privée frontalier

June 11. 2011 04:47

Gravatar

Great site design!!!! Whattemplate did you use?

Christian Louboutin

June 12. 2011 20:55

Gravatar

Great site design!!!! Whattemplate did you use?

Pandora Beads

July 31. 2011 13:50

Gravatar

Thanks for sharing it!

DCUO Cash

August 6. 2011 23:47

Gravatar

These risks not only originate from outside the organization, but also from within.

DCUO Cash

September 30. 2011 04:51

Gravatar

Apparently risk management is the set of processes through which management identifies, analyzes, and, where necessary, responds appropriately to risks that might adversely affect realization of the organization's business objectives

quality writing service

November 13. 2011 10:14

Gravatar

I'll gear this review to 2 types of people: current Zune owners who are considering an upgrade, and people trying to decide between a Zune and an iPod. (There are other players worth considering out there, like the Sony Walkman X, but I hope this gives you enough info to make an informed decision of the Zune vs players other than the iPod line as well.)

Her Shampoo

November 14. 2011 08:50

Gravatar

Sorry for the huge review, but I'm really loving the new Zune, and hope this, as well as the excellent reviews some other people have written, will help you decide if it's the right choice for you.

Sulfate Free Shampoo

Add comment


(Will show your Gravatar icon)  

  Country flag




Live preview

February 5. 2012 11:05

Gravatar