|
Seven instructions for IT security practitioners to express themselves in terms that are meaningful to business leaders in alignment with the broader ERM activities are to:
- Create a universally accepted definition of convergence and ERM.
- Learn the language of the ERM role.
- Map broader IT and business objectives to information security risks.
- Leverage educated guesswork and personal judgments.
- Strive for profiles and do regular cyberdragnet investigations.
- Use common sense when treating traditional information security risks.
- Make clear the enterprise’s objectives for ERM.
|