Saturday, May 19, 2012
  • Resource Center
  • Support
  • Contact Us
  • Products
    • SpyLogix Enterprise
      1. SpyLogix Platform
      2. SpyLogix Modules
        • Active Directory
        • Windows Server
        • User Security
        • FIM 2010
        • LDAP Directories
        • CA SiteMinder
        • VMware vSphere
        • IBM System z and i
        • Module SDK
      3. SpyLogix Architecture
    • SpyLogix for Microsoft
      1. Active Directory
      2. Windows Server
      3. User Security
      4. FIM 2010
    • IDx Identity Assurance Suite
      1. IDx Voice Self Service Password Reset
  • Solutions
    • SpyLogix Key Benefits
    • Cloud Solutions
    • Microsoft Solutions
    • Government Solutions
    • Identity Assurance Solutions
    • Information Security Solutions
  • Partners
    • Overview
    • System Integrators
    • Cloud Service Partners
    • Technology Partners
    • Become an IdentityLogix Partner
  • News & Events
    • Events
    • Webinars
    • Press Releases
    • In The News
  • Company
    • About Us
    • Careers
    • Support
    • Contact Us
  • Blog
onthebeachblog3
  • Subscribe to updates
  • Print
  • PDF
  • Bookmark
Gary Sheehan

In My Humble Opinion

By Gary Sheehan on
Gary Sheehan
Gary is the Director of GRC Services for Advanced Server Management Group, Inc.
User is currently offline
Jan 12 in IT GRC 0 Comments
Tweet

All companies know they should abstain from bad business practices, protect their business assets, minimize their risk and make as much money as they can. Most businesses that have a penchant for losing money and a knack for failing to meet their company goals know they should make certain changes to their business plans to improve their bottom line. Yet, I believe far fewer actually do so. So how can CIOs motivate and educate their colleagues to follow through in choosing the behaviors and techniques that help build and promote healthy companies? Let’s take a look at three elements that have a huge impact on the safety, health, profitability and longevity of every company.

Doing the right things. It is important for IT organizations to have a consistent set of processes, customs, policies, laws and organizational structures that encourage employees and officers of the company to do the right things. CIOs can ensure the investment in IT generates business value and mitigates the risks that are associated with IT by using proven frameworks and best practices associated with IT governance. Frameworks like COBIT and ISO 38500 can guide CIOs through the PDCA cycle to promote good governance and continuous improvement within their IT environment.

 

Identifying and managing risks. Effectively managing risk provides the foundation for a good security program. All security-related government regulations, industry regulations, privacy requirements, frameworks and best practices identify risk management as a critical need for every organization. CIOs can balance the operational and economic costs of protective measures and the gains achieved in meeting business goals by adopting a meaningful risk management methodology. A meaningful risk methodology is one that provides accurate information, aligns to the business and its critical processes, can be used throughout the organization and is used and understood by key stakeholders to make business decisions.

 

Complying with voluntary and mandatory requirements. Government and industry are beginning to crack down on organizations that have weak or non-existent compliance procedures. More legislation at the federal and state levels is being considered to force companies to comply with industry best practices. In essence, compliance is directly related to corporate integrity and good governance practices. If a company practices what it preaches and follows the rules which govern its business, then doing the right things and managing its risk become standard operating procedures. CIOs should design and implement an IT strategy that promotes and satisfies compliance, ethics, accountability, cultural, financial, business and legal obligations.

 

Taking an integrated approach to governance, risk and compliance (GRC) will help to ensure that CIOs meet their responsibilities for doing the right things, managing risks and complying with voluntary and mandatory requirements. There are a number of frameworks, organizations, technologies and best practices that CIOs can use to design and implement their GRC strategies. It is no longer wise or acceptable to say GRC is not part of our jobs.

 

 

Tags: GRC, IT GRC, risk assessment, ISO38500, COBIT
Hits: 124
Rate this blog entry
1 vote
  • My First Foray Into Tech Blogging / A Hot-Swap Plu...
  • Utilities GRC Smart Meter/Grid Realization
  • Author
  • Related Posts
  • Trackbacks

About the author

Gary Sheehan

Gary is the Director of GRC Services for Advanced Server Management Group, Inc. He has over 25 years experience in information technology with over 20 years experience in information security, specializing in GRC integration, security management, assessments, policy and awareness development, compliance and security program implementation.

Gary can be reached at gsheehan@asmgi.com if you have comments or questions.
http://gsheehan@asmgi.com

Trackbacks

Trackback URL for this blog entry

Related Posts

  • SmartGrid Breakaway Capability

    Using NISTIR 7628 and NISTIR 7756
    By Steven Phipps on - Aug 08 in IT GRC
  • Utilities GRC Smart Meter/Grid Realization

    While participating in smart meter / smart grid programs, we have seen cash flow optimization by improving revenue realization and reducing costs for ...
    By Steven Phipps on - Apr 18 in IT GRC
  • PCI 2.0 from PCI 1.2 Compliances Challenges to Organizations

    Organizations must track and monitor all access to cardholder data and related network resources – in stores, regional offices, headquarters, and othe...
    By Steven Phipps on - Apr 20 in IT GRC
  • Customer Meter-to-Cash Reduction in Energy Consumption & Billing

    We have voiced to utilities that implementation and/or replacement of energy devices onto residential, commercial and industrial buildings and househo...
    By Steven Phipps on - May 02 in IT GRC

Comments

No comments made yet. Be the first to submit a comment

Leave your comment

Loading
Guest
Guest Saturday, 19 May 2012
Member Login

Categories

GRC
3 post(s)
IT GRC
2 post(s)
Code
1 post(s)
PCI
1 post(s)

Bloggers

Gary Sheehan
Gary Sheehan
1 post(s)
"Gary is the Director of GRC Services for Advanced ..."
http://gsheehan@asmgi.com
Blaise Boscaccy
Blaise Boscaccy
1 post(s)
"IdentityLogix VP of Product Development"
Steven Phipps
Steven Phipps
5 post(s)
"Steven is IdentityLogix Vice President Profession ..."

Join Us

Tag Cloud

NIST 800-53 IT GRC NISTIR 7756 Smart Grid Smart Grid NERC-CIP NISTIR 7628 Regulatory Assess MDMS Report Continuous Monitoring PCI DSS eGRC real-time .NET C Sharp Utilities AMI PCI 2.0 Compliance Monitor ISO 27002 PCI 1.2 CCM risk assessment Asset Management plugin code C# PCI Continuous Control Monitoring Smart Meter Energy M2C Audit COBIT CAESARS ISO38500 GRC Remediate

Follow Us

identitylogix's avatar
IdentityLogix identitylogix
Loading...

Last 4 tweets from identitylogix:

People talking about '@identitylogix':

  • Solutions
  • Products
  • Partners
  • News & Events
  • Company
  • Legal Notice
  • Privacy Policy
  • Contact Us
© Copyright 2010, IdentityLogix, All Rights Reserved.

Login

  • Forgot your password?
  • Forgot your username?