Subscribe

Archive for the ‘Information Security’ Category

You are currently browsing the archives for the Information Security category.

New Research: How Mature is Your IT Risk Management?

By John Kelly September 1st, 2009 in: Customer Spotlight, IT Risk and Compliance, Information Security

How effective is your organization at identifying and managing IT risks? Does your organization think of IT risk only in terms of avoidance or compliance, or does it use risk management to improve the effectiveness and value of IT?

If you’ll complete this short, 5 minute survey on IT risk management, we’ll send you a [...]

[Read More]

GRC and the CISO

By Gordon Burnes August 19th, 2008 in: Governance, Risk and Compliance (GRC), Information Security

GRC is touching just about everyone these days.  A lot has been written about the CFO, CRO, CCO and CIO and their roles in deploying GRC technologies.  Mike Rothman at the Daily Incite writes here about the CISO’s role in deploying GRC solutions and makes the point that CISO’s should be focused not on implementing [...]

[Read More]

New PCI DSS Standard Due Out

By Gordon Burnes April 15th, 2008 in: IT Risk and Compliance, Information Security

SearchSecurity has coverage from RSA about a new version of the PCI Data Security Standard, due out sometime in Q3 of this year. It appears they’re taking a pragmatic approach, and indications are that it will be an evolution based on user feedback rather than a drastic, revolutionary change. PCI has been a sensitive topic, [...]

[Read More]

Myth Nine: TJX — It Can’t Happen Here

By Gordon Burnes February 27th, 2008 in: IT Risk and Compliance, Information Security, Myths, Operational Risk

Attrition.org maintains a list of public, high profile data breaches. The list is staggeringly long, and goes back to the year 2000. TJX, while a high profile data breach and perhaps one of the biggest stories of 2007, is only one of the many that were publicly reported. And, companies have a vested interest in [...]

[Read More]

Myth One: IT Risk Management = Information Security

By Gordon Burnes January 25th, 2008 in: IT Risk and Compliance, Information Security, Myths

In November, I blogged about the difference between IT Risk Management and Information Security. For the full post, read here.
There’s a big different between tactical execution and strategic oversight. Therein comes the challenge with most information security programs; they place far too much emphasis on the how and what, and far too little on the [...]

[Read More]

Manage Information Risk – Not Information Security

By Gordon Burnes November 7th, 2007 in: Enterprise Risk Management (ERM), IT Risk and Compliance, Information Security

When I took my first class on financial engineering as a naïve applied mathematics undergrad, we started with portfolio selection and the capital asset pricing model. In my typically confident (some might say arrogant ) fashion, I decided I knew more than the professors, and that we should be focused on maximizing returns, rather than [...]

[Read More]
Search Blog
OpenPages Bloggers
Gordon Burnes
Gordon BurnesVice President of Marketing
John Kelly
John KellyDirector of Marketing
Patrick O'Brien
Patrick O'BrienDirector of Product Management
Guest Bloggers
Richard M. Steinberg
Richard M. SteinbergFounder & CEO, Steinberg Governance Advisors, Inc.
John A. Wheeler
John A. WheelerFounder & Managing Principal, Wheelhouse Advisors LLC
OpenPages® and Clarity, Confidence and Control® are registered trademarks of OpenPages, Inc.