|
|
05 February, 2008 06:52 PM EST Defining Risk Management
Posted By: Paul Proctor, Research VP
The rise of risk management as both a discipline and a reference has led to confusion in terminology and applicability. The word "risk" has proliferated in titles for traditional roles and responsibilities such as security, business continuity, privacy and many operations functions. In some cases, this is nothing more than a title change with no fundamental shift in methodology. This proliferation has led organizations to struggle at the top with clearly defining what enterprise risk management (ERM) means to their organization, and at the bottom with defining what "risk" people do vs. their counterparts in traditional operational roles. Even within the various risk management groups, organizations must clearly define how responsibility is assigned. COMMENTS
11 February, 2008 12:39 PM EST This is a topic that is being thought about extensively within my organization right now. "Risk Management" is a term that has been used with far too little rigor, to say the least. Much of what a security organization does is about providing appropriate governance and operations activity, but it has all been wrapped up in this title of risk management. Some research and insight into what is effective in other organizations would definitely help.
|
Search The Blog
Archives
Recommended Links
Organizations/Publications
Compliance
Contact
To learn more, please contact:
Gartner Office: + 1 203 964 0096 sitefeedback@gartner.com help@gartner.com Contact Us Form Worldwide General Contacts |
|||||||||||||||||||||||||||||||||||||||||||||||||
|
© = date("Y"); ?> Gartner, Inc. and/or its Affiliates. All Rights Reserved.
|
||||||||||||||||||||||||||||||||||||||||||||||||||