Skip Links

Network World

  • Social Web 
  • Email 
  • Close

7 steps to effective risk management

Many enterprises lack consistency when it comes to applying risk management
IT Leadership Alert By Amy Schurr , Network World , 05/27/2008
Sign up for this newsletter now!

Amy Schurr dispenses advice on managing human and capital assets for maximum ROI.

  • Share/Email
  • Tweet This
  • Comment
  • Print

When your organization talks about risk management, what does it mean? According to Gartner, many enterprises are inconsistent in the use and application of the term. So it's no surprise that risk management often ends up siloed into separate functional areas such as business continuity, security, management and privacy.

Gartner’s recent report, "A Risk Hierarchy for Enterprise and IT Risk Managers," emphasizes the need for a holistic view of risk. "An enterprise that wishes to better understand and manage the risks to which it is exposed should begin with enterprise-specific risk definitions and an organizational risk hierarchy to which all risk-related specialists can align," says Paul Proctor, vice president and distinguished analyst at the IT research firm. "Although no single definition will work for all enterprises, it is important to start from a common, overarching framework to eliminate overlap, avoid gaps in coverage and ensure good governance."

In order to make risk management more effective in your IT organization, Gartner offers 7 steps:

1. Implement a framework for risk assessment and mapping.
2. Outline the responsibilities of risk managers with their respective domains.
3. Identify and define the risks to which the business is exposed and how to map incidents.
4. Determine the threat level and focus on the risk that have the greatest potential to affect enterprise performance.
5. Establish levels of controls for processes commensurate with the perceived threat.
6. Record and retain risk incident and near-miss information.
7. Conduct periodic risk assessments to determine changes in your company’s risk profile and assess performance.

Amy Schurr is the former managing features editor of Network World.

  • Share/Email
  • Tweet This
  • Comment
  • Print
Partner Content

NetScout and analyst Jim Metzler have teamed to deliver a series of IT Briefs on Network and Application Performance Management leveraging research from NetScout's nGenius & Sniffer users.

www.netscout.com

Metzler on Service Delivery Management

Delivering IT business value by evolving our thinking from managing application performance to focusing on services.

Learn More

2009 Handbook of Application Delivery

Successful IT organizations must know how to make the right application delivery decisions in these tough economic times.

Download the Handbook

Metzler on the Modern IP Network

Discusses the growing emphasis on network management and the need to implement a holistic view of the end-to-end experience of the user.

Read the Brief

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed