{"id":67,"date":"2009-02-19T17:42:02","date_gmt":"2009-02-19T12:12:02","guid":{"rendered":"https:\/\/www.qadit.com\/blog\/?p=67"},"modified":"2009-03-05T18:49:59","modified_gmt":"2009-03-05T13:19:59","slug":"it-governance-institute%e2%80%99s-new-framework-risk-it","status":"publish","type":"post","link":"https:\/\/qadit.com\/blog\/it-governance-institute%e2%80%99s-new-framework-risk-it\/","title":{"rendered":"IT Governance Institute\u2019s New Framework-Risk IT"},"content":{"rendered":"<p>IT risk is gaining increased attention from executive management, stakeholders and regulators alike. The COBIT framework provides a generally accepted framework for IT but this does not deal with risk management in a comprehensive manner. The ITGI has now remedied this gap with their latest initiative-a\u00a0framework\u00a0for IT related\u00a0risk management.<!--more--><\/p>\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; text-align: justify;\">\n<p>On Feb 4, 2009, the IT Governance issued an exposure draft of its research publication Enterprise Risk: Identify Govern and Manage Risk, The Risk IT Framework. This IT enterprise risk management framework is designed to allow business managers to identify and assess IT-related business risks and manage them effectively. It provides the missing link between enterprise risk management (ERM) and IT risk management and control, fitting in the overall IT governance framework of ITGI, and building upon all existing risk related components within the current frameworks, i.e., COBIT and Val IT.<\/p>\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; text-align: justify;\">\n<div><span style=\"font-size: 10pt; font-family: &quot;Microsoft Sans Serif&quot;;\">The exposure draft is posted for 45 day public exposure and comment. At the conclusion of the exposure period, the authors will use the feedback, comments and suggestions provided to improve the publication for issue. A link to the exposure draft and online questionnaire is posted in the ITGI <a href=\"https:\/\/www.itgi.org\">www.itgi.org<\/a> and ISACA <a href=\"https:\/\/www.www.isaca.org\">www.isaca.org<\/a> home pages.<\/span><\/div>\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; text-align: justify;\">\n<div class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; text-align: justify;\"><span style=\"font-size: 10pt; font-family: &quot;Microsoft Sans Serif&quot;;\"><br \/>\n<strong>This document provides a high level overview of this framework and the reason behind this initiative.\u00a0 It will cover some basic concepts relating to IT related risk, frameworks and how existing frameworks measure up.Subsequent blog entries will provide insights into the frameworks key concepts and definitions.<\/strong><\/span><\/div>\n<div class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; text-align: justify;\"><span style=\"font-size: 10pt; font-family: &quot;Microsoft Sans Serif&quot;;\"><strong><br \/>\n<\/strong><\/span><\/div>\n<p class=\"MsoNormal\" style=\"margin: 0in 0in 0pt; text-align: justify;\">\n<ul style=\"MARGIN-TOP: 0cm\" type=\"disc\">\n<li class=\"MsoNormal\"><strong>IT related Risk Management<\/strong><\/li>\n<\/ul>\n<p class=\"MsoNormal\" style=\"MARGIN: 0cm 0cm 0pt 18pt\">\n<p class=\"MsoNormal\" style=\"MARGIN: 0cm 0cm 0pt 18pt\"><span style=\"FONT-SIZE: 10pt; FONT-FAMILY: Tahoma\">This covers all IT related risks and is not just to Information Security. Examples include inadequate resources, obsolete infrastructure, staff with inadequate skills etc. In short it covers all business risks arising from IT related activities<\/span><\/p>\n<p class=\"MsoNormal\" style=\"MARGIN: 0cm 0cm 0pt 18pt\"><span style=\"FONT-SIZE: 10pt; FONT-FAMILY: Tahoma\"><br \/>\n<\/span><\/p>\n<p class=\"MsoNormal\" style=\"MARGIN: 0cm 0cm 0pt 18pt\"><span style=\"FONT-SIZE: 10pt; FONT-FAMILY: Tahoma\"> <\/span><\/p>\n<ul style=\"MARGIN-TOP: 0cm\" type=\"disc\">\n<li class=\"MsoNormal\"><strong><span style=\"FONT-SIZE: 10pt; FONT-FAMILY: Tahoma\">Essentials of a good risk management framework for IT related risk<\/span><\/strong><\/li>\n<\/ul>\n<p class=\"MsoNormal\" style=\"MARGIN: 0cm 0cm 0pt 18pt\">\n<p class=\"MsoNormal\" style=\"MARGIN: 0cm 0cm 0pt 18pt\"><span style=\"FONT-SIZE: 10pt; FONT-FAMILY: Tahoma\">The following are the essential features of risk management framework-<\/span><\/p>\n<ol style=\"MARGIN-TOP: 0cm\" type=\"a\">\n<li class=\"MsoNormal\"><span style=\"FONT-SIZE: 10pt; FONT-FAMILY: Tahoma\">Provides comprehensive coverage and not restrict itself to the technical aspects of IT.<\/span><\/li>\n<li class=\"MsoNormal\"><span style=\"FONT-SIZE: 10pt; FONT-FAMILY: Tahoma\">IT related focus<\/span><\/li>\n<li class=\"MsoNormal\"><span style=\"FONT-SIZE: 10pt; FONT-FAMILY: Tahoma\">Covers the full IT life cycles i.e. broadest view on IT related risk<\/span><\/li>\n<li class=\"MsoNormal\"><span style=\"FONT-SIZE: 10pt; FONT-FAMILY: Tahoma\">Translates IT related risks into impact on business<\/span><\/li>\n<li class=\"MsoNormal\"><span style=\"FONT-SIZE: 10pt; FONT-FAMILY: Tahoma\">Provides a continuous process from risk identification to continuous monitoring and feedback.<\/span><\/li>\n<li class=\"MsoNormal\"><span style=\"FONT-SIZE: 10pt; FONT-FAMILY: Tahoma\">Provides risk treatment options<\/span><\/li>\n<li class=\"MsoNormal\"><span style=\"FONT-SIZE: 10pt; FONT-FAMILY: Tahoma\">It should be easily accessible\/available to users-easily downloadable, not expensive<\/span><\/li>\n<\/ol>\n<p class=\"MsoNormal\" style=\"MARGIN: 0cm 0cm 0pt 18pt\"><span style=\"FONT-SIZE: 10pt; FONT-FAMILY: Tahoma\"> <\/span><\/p>\n<ul style=\"MARGIN-TOP: 0cm\" type=\"disc\">\n<li class=\"MsoNormal\"><strong><span style=\"FONT-SIZE: 10pt; FONT-FAMILY: Tahoma\">How does COBIT stack up against these essential features:<\/span><\/strong><\/li>\n<\/ul>\n<p class=\"MsoNormal\" style=\"MARGIN: 0cm 0cm 0pt; mso-list: l1 level1 lfo1; tab-stops: list 36.0pt\"><span style=\"FONT-SIZE: 10pt; FONT-FAMILY: Tahoma\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-71\" src=\"https:\/\/www.qadit.com\/blog\/wp-content\/riskiteval.jpg\" alt=\"riskiteval\" width=\"788\" height=\"400\" srcset=\"https:\/\/qadit.com\/blog\/wp-content\/uploads\/riskiteval.jpg 788w, https:\/\/qadit.com\/blog\/wp-content\/uploads\/riskiteval-300x152.jpg 300w\" sizes=\"auto, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px\" \/><\/span><\/p>\n<p class=\"MsoNormal\" style=\"MARGIN: 0cm 0cm 0pt 18pt\"><span style=\"FONT-SIZE: 10pt; FONT-FAMILY: Tahoma\">As can be seen from the graphic above COBIT provides limited guidance on risk management. Reference to risk management is limited to Process P09 of CoBIT 4.1. A similar evaluation of other frameworks COSO-ERM, ISO27000 series produced the same results. These frameworks provided only a partial coverage of IT related risk management.<\/span><\/p>\n<p class=\"MsoNormal\" style=\"MARGIN: 0cm 0cm 0pt 18pt\"><span style=\"FONT-SIZE: 10pt; FONT-FAMILY: Tahoma\"> <\/span><\/p>\n<p class=\"MsoNormal\" style=\"MARGIN: 0cm 0cm 0pt 18pt\"><strong><span style=\"FONT-SIZE: 10pt; FONT-FAMILY: Tahoma\">The summary of this evaluation is shown below:<\/span><\/strong><span style=\"FONT-SIZE: 10pt; FONT-FAMILY: Tahoma\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-72\" src=\"https:\/\/www.qadit.com\/blog\/wp-content\/riskiteval2.gif\" alt=\"GAP Analysis of other Frameworks\" width=\"623\" height=\"372\" \/><\/span><\/p>\n<p class=\"MsoNormal\" style=\"MARGIN: 0cm 0cm 0pt 18pt\"><span style=\"FONT-SIZE: 10pt; FONT-FAMILY: Tahoma\">So for e.g. COSO scores really high on the completeness of risk management scope but it does not provide in-depth coverage of IT. So is essence there is no comprehensive IT related risk management framework currently available.<\/span><\/p>\n<p class=\"MsoNormal\" style=\"MARGIN: 0cm 0cm 0pt 18pt\"><span style=\"FONT-SIZE: 10pt; FONT-FAMILY: Tahoma\"><br \/>\n<\/span><\/p>\n<p class=\"MsoNormal\" style=\"MARGIN: 0cm 0cm 0pt 18pt\"><span style=\"FONT-SIZE: 10pt; FONT-FAMILY: Tahoma\"> <\/span><\/p>\n<p class=\"MsoNormal\" style=\"MARGIN: 0cm 0cm 0pt 18pt\"><span style=\"FONT-SIZE: 10pt; FONT-FAMILY: Tahoma\"> <\/span><\/p>\n<ul style=\"MARGIN-TOP: 0cm\" type=\"disc\">\n<li class=\"MsoNormal\"><strong><span style=\"FONT-SIZE: 10pt; FONT-FAMILY: Tahoma\">The Risk IT Framework (Risk IT)<\/span><\/strong><\/li>\n<\/ul>\n<p class=\"MsoNormal\" style=\"MARGIN: 0cm 0cm 0pt 18pt\"><span style=\"FONT-SIZE: 10pt; FONT-FAMILY: Tahoma\">Risk IT framework has been defined by the ITGI to ensure that this framework will bridge the gap in the comprehensiveness\/coverage space. The framework will address all risk management activities and domains and not just controls (as is the case with COBIT). It will cover all IT related risks that will affect realization on business objectives.<\/span><\/p>\n<p class=\"MsoNormal\" style=\"MARGIN: 0cm 0cm 0pt 18pt\"><span style=\"FONT-SIZE: 10pt; FONT-FAMILY: Tahoma\"> <\/span><span style=\"FONT-SIZE: 10pt; FONT-FAMILY: Tahoma\"> <\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>IT risk is gaining increased attention from executive management, stakeholders and regulators alike. The COBIT framework provides a generally accepted framework for IT but this does not deal with risk management in a comprehensive manner. The ITGI has now remedied this gap with their latest initiative-a\u00a0framework\u00a0for IT related\u00a0risk management.<\/p>\n","protected":false},"author":5,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false},"version":2}},"categories":[24],"tags":[30,29,31,28],"class_list":["post-67","post","type-post","status-publish","format-standard","hentry","category-grc","tag-governance","tag-qadit","tag-risk-compliance","tag-riskit"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p9AH7Q-15","_links":{"self":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/posts\/67","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/comments?post=67"}],"version-history":[{"count":0,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/posts\/67\/revisions"}],"wp:attachment":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/media?parent=67"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/categories?post=67"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/tags?post=67"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}