Acceptance is often a reasonable strategy for InfoRisk.
Who does the accepting?
If you have one omnipotent Risk Manager who calls the shots, the answer is simple.
But, to create a risk culture, Risk Management will have to take place on multiple levels.
Suppose the Network Dept assess a certain risk, can they accept it on behalf of the organization? If yes, how are they in a position to judge (and accept) the business impact? If no, how can Risk Mgmt be scalable unless responsibility is delegated?
(some of) my events
- 2023-05-11 Certifierad IT-arkitekt (guest lecturing, Stockholm)
- 2023-01-16---05-28 Sound Engineering I (taking course, Örebro University)
- 2022-11-07---01-13 Measurement Theory and Philosophy of Value (taking course, University of Gävle)
- 2022-12-05 Datavetenskapliga programmet (guest lecturing, University of Gävle)
- 2022-12-01 Riskförmiddag with Riskkollegiet (lecturing at seminar, Uppsala University)
2014-06-30
2014-06-14
Stockholm Criminology Symposium
This week I attended the 9th Stockholm Criminology Symposium. Not being a practitioner in crime prevention and having taken just an introductory course, some of the research stuff is way beyond me. So, why go there?
Applied InfoSec can use input from more mature fields. Preventing bad things from happening. Motivating individuals to choose the narrow track. Governing change.
Also, I enjoy venturing out of the silo, meeting people more knowledgeable than myself with entirely different experiences and tools.
Applied InfoSec can use input from more mature fields. Preventing bad things from happening. Motivating individuals to choose the narrow track. Governing change.
Also, I enjoy venturing out of the silo, meeting people more knowledgeable than myself with entirely different experiences and tools.
from command-and-control to a servant leadership. involvement, motivation, innovation, relevant metrics for policing. #sthlmcrimsymposium
— per stromsjo « (@stromsjo) June 11, 2014
2014-06-13
change is in the air
I've been an employee of the Swedish bank SEB since 1991, initially as a database specialist, then working with applied information security since 2006.
Having spent 23 good years in the financial sector, following this summer I will take up a position as consultant in the great team of Konsultbolag1 InfoSec AB.
As always in consulting, what I will be doing will be up to our customers, but I look forward to driving change within the field of security by means of teaching, coaching and mentoring.
Having spent 23 good years in the financial sector, following this summer I will take up a position as consultant in the great team of Konsultbolag1 InfoSec AB.
As always in consulting, what I will be doing will be up to our customers, but I look forward to driving change within the field of security by means of teaching, coaching and mentoring.
2014-06-09
Inter-Organizational Information Risk
Information handling can be outsourced. Accountability can not. When things go wrong, the image loss remains with the owner.
Risk is managed at multiple levels.
Organization: clarify boundaries of responsibility, align policies and practices, establish process
System: assign risk ownership - what if our assets are transmitted through your infrastructure?
Individual: which person carries which role?
When systems transcend boundaries of organizations, how do we make sure the ball is not dropped?
Risk is managed at multiple levels.
Organization: clarify boundaries of responsibility, align policies and practices, establish process
System: assign risk ownership - what if our assets are transmitted through your infrastructure?
Individual: which person carries which role?
When systems transcend boundaries of organizations, how do we make sure the ball is not dropped?
Subscribe to:
Posts (Atom)
20230209