Network World
Friday, November 21, 2008
DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Community: Security

Navigation

G, R and C have little in common?

I wish to disagree with Bob Blakley’s claim that "GRC (Governance, Risk Management and Compliance) had little in common and are not one concept and should all be treated separately." Risk can be thought of as the need to measure the possibility of an impact and how to mitigate it. Compliance can be thought of as the need to meet a policy (legal or otherwise), often due to a perceived risk. Governance can be thought of as the processes that manage risk and compliance. All three should be examined by IT auditors. They should be considered as interdependent in their implementation. Any enterprise that treats them separately will not derive the inherent synergies. A good example in the IT and IAM world is the synchronisation of the Identity Directory with platforms and applications that a user is authorised to access. Some implementations such as IBM’s TIM provide the capability of automated synchronisation as a closed-loop (i.e. they can't get out of step). This real-time "reconciliation" meets RBAC policies (governance), reduced incidence of security and fraud related activity (risk) and meets SOX (compliance). This happens immediately and constantly, rather than once every six months if done independently. G, R and C have little in common? I don’t think so. Allan Milgate

Click to read the article this is in response to.

Post new comment

The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <i> <b> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <blockquote> <br /> <br> <p>
  • Lines and paragraphs break automatically.
  • You can use BBCode tags in the text.
  • Web page addresses and e-mail addresses turn into links automatically.

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.

Advertisement: