Policy is created to control risk exposure. Failing to establish coherent and adequate policy drives risk. Classify your assets, test your systems, educate your employees - says the policy. Risk reduction through compliance.
And the other way round. Ensure that design decisions are explicitly risk-based, says the policy. Compliance through risk management.
Can you see other ways in which the risk (manage potential consequences) and compliance (do as we're told) perspectives are interrelated?
(some of) my events
- 2023-05-11 Certifierad IT-arkitekt (guest lecturing, Stockholm)
- 2023-01-16---05-28 Sound Engineering I (taking course, Örebro University)
- 2022-11-07---01-13 Measurement Theory and Philosophy of Value (taking course, University of Gävle)
- 2022-12-05 Datavetenskapliga programmet (guest lecturing, University of Gävle)
- 2022-12-01 Riskförmiddag with Riskkollegiet (lecturing at seminar, Uppsala University)
2014-02-03
2014-02-01
the rest is Risk
In the beginning there was Compliance.
Until our information systems grew complex and interconnected, the Compliance perspective served us fairly well. There was comfort in trusting that Knowledgeable Others had already foreseen what could possibly go wrong and devised clever rules to keep us safe. Do this or that and be secure.
Those were the days.
By now, we have more rules than ever and we still need to follow them. But complying is not enough anymore, we have to fend for ourselves.
The rest is Risk.
Until our information systems grew complex and interconnected, the Compliance perspective served us fairly well. There was comfort in trusting that Knowledgeable Others had already foreseen what could possibly go wrong and devised clever rules to keep us safe. Do this or that and be secure.
Those were the days.
By now, we have more rules than ever and we still need to follow them. But complying is not enough anymore, we have to fend for ourselves.
The rest is Risk.
Subscribe to:
Posts (Atom)
20230209