Enterprise Risk Management (ERM) has been around at least since the days of the Trojan Horse. Information security risk management can learn much from ERM and avoid reinventing the wheel. The National Association of Corporate Directors (NACD) made this clear in the 2014 handbook Cyber Risk Oversight. Principle #1 is to approach cybersecurity as an enterprise wide risk management issue. For updated observations on ERM and information security, go to my CSO Online blog post “Don’t be the next Humpty Dumpty”….
*** This is a Security Bloggers Network syndicated blog from Security Connections authored by Frederick Scholl. Read the original post at: https://www.monarch-info.com/blog_direct_link.cfm?blog_id=63852&Enterprise-Risk-Management-and-Information-Security