<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IT Governance, Risk, and Compliance &#187; Enterprise Governance</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/it-governance/tag/enterprise-governance/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/it-governance</link>
	<description></description>
	<lastBuildDate>Mon, 17 Jun 2013 01:33:42 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Risk Management: Is it just another set of business buzzwords? – Part VIII</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/risk-management-is-it-just-another-set-of-business-buzzwords-part-viii/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/risk-management-is-it-just-another-set-of-business-buzzwords-part-viii/#comments</comments>
		<pubDate>Thu, 21 Mar 2013 01:02:03 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[Administrative Control]]></category>
		<category><![CDATA[Asset Management]]></category>
		<category><![CDATA[Business Continuity]]></category>
		<category><![CDATA[Continuity Management]]></category>
		<category><![CDATA[Crisis Management]]></category>
		<category><![CDATA[Decision Making]]></category>
		<category><![CDATA[Due Care]]></category>
		<category><![CDATA[Due Diligence]]></category>
		<category><![CDATA[Enterprise Governance]]></category>
		<category><![CDATA[Event Management]]></category>
		<category><![CDATA[Incident Management]]></category>
		<category><![CDATA[Information Technology]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[IT Management]]></category>
		<category><![CDATA[Management Information System]]></category>
		<category><![CDATA[Operating Style]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Threat Management]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=1901</guid>
		<description><![CDATA[IT policies, directives, standards, procedures, and rules should be deployed based on assessed effectiveness and efficiency in addressing managements risk appetite. Deployed controlling and monitoring activities should reflect management’s strategy for ensuring an adequate IT control system. IT control policies and directives can be considered high-level governance documentation while standards, procedures, and rules can be [...]]]></description>
				<content:encoded><![CDATA[<p>IT policies, directives, standards, procedures, and rules should be deployed based on assessed effectiveness and efficiency in addressing managements risk appetite. Deployed controlling and monitoring activities should reflect management’s strategy for ensuring an adequate IT control system. IT control policies and directives can be considered high-level governance documentation while standards, procedures, and rules can be considered detail-level governance documentation. Normally, oversight committees and executive management utilize high-level governance documents to provide general control direction. Whereby, lower-level management converts high-level governance documents into detail-level IT governance documents assisting in ensuring control objective achievement. Developing and implementing IT governance design effectiveness and efficiency can be a multidirectional, interactive, iterative, and <em>adaptive process</em>.</p>
<p>Source</p>
<p>Davis, Robert E. (2011). <em>Assuring IT Governance</em>. Available from <a href="http://www.amazon.com/Assuring-Governance-Assurance-Services-ebook/dp/B0058P58E0">http://www.amazon.com/Assuring-Governance-Assurance-Services-ebook/dp/B0058P58E0</a> and <a href="http://www.smashwords.com/books/view/70359">http://www.smashwords.com/books/view/70359</a></p>
<p>Davis, Robert E. (2006). <a title="IT Auditing: IT Governance" href="http://www.theiia.org/bookstore/product/it-auditing-it-governance-1273.cfm" target="_blank"><em>IT Auditing: IT Governance</em></a>. Mission Viejo: Pleier. CD-ROM.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/risk-management-is-it-just-another-set-of-business-buzzwords-part-viii/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Risk Management: Is it just another set of business buzzwords? – Part VII</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/risk-management-is-it-just-another-set-of-business-buzzwords-part-vii/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/risk-management-is-it-just-another-set-of-business-buzzwords-part-vii/#comments</comments>
		<pubDate>Sat, 16 Mar 2013 15:40:08 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[Administrative Control]]></category>
		<category><![CDATA[Asset Management]]></category>
		<category><![CDATA[Business Continuity]]></category>
		<category><![CDATA[Continuity Management]]></category>
		<category><![CDATA[Crisis Management]]></category>
		<category><![CDATA[Decision Making]]></category>
		<category><![CDATA[Due Care]]></category>
		<category><![CDATA[Due Diligence]]></category>
		<category><![CDATA[Enterprise Governance]]></category>
		<category><![CDATA[Event Management]]></category>
		<category><![CDATA[Incident Management]]></category>
		<category><![CDATA[Information Technology]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[IT Management]]></category>
		<category><![CDATA[Management Information System]]></category>
		<category><![CDATA[Operating Style]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Threat Management]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=1888</guid>
		<description><![CDATA[Management should establish standards as baselines for measuring quantity, weight, extent, value, or quality.  Standards can be considered specific goals or objectives against which performance is compared.  Selection of points where performance will be measured is critical to effective standards.  Employee accountability affects responsibility for meeting standards.  Consequently, responsibility for a standard should be directly [...]]]></description>
				<content:encoded><![CDATA[<p>Management should establish <strong>standards</strong> as baselines for measuring quantity, weight, extent, value, or quality.  Standards can be considered specific goals or objectives against which performance is compared.  Selection of points where performance will be measured is critical to effective standards.  Employee accountability affects responsibility for meeting standards.  Consequently, responsibility for a standard should be directly correlated to activity responsibility.  Without accountability, standards become ineffective measurement tools.</p>
<p><strong>Procedures</strong> establish methods for accomplishing an activity, through specific performance, while simultaneously complying with prescribed policies. Prior to determining procedures, processes should be identified and classified to determine control objective impact. In order to create an adequate IT governance framework, management must understand and document operational procedures.</p>
<p><strong>Rules</strong> are specific and detailed guides that confine and restrict behavior. Comparatively, rules are the simplest operational plan. A rule requires a specific action to be taken regarding a given situation. For example, “This building is a smoke free environment. Violators will be dismissed without exception.”</p>
<p>Source</p>
<p>Davis, Robert E. (2011). <em>Assuring IT Governance</em>. Available from <a href="http://www.amazon.com/Assuring-Governance-Assurance-Services-ebook/dp/B0058P58E0">http://www.amazon.com/Assuring-Governance-Assurance-Services-ebook/dp/B0058P58E0</a> and <a href="http://www.smashwords.com/books/view/70359">http://www.smashwords.com/books/view/70359</a></p>
<p>Davis, Robert E. (2006). <a title="IT Auditing: IT Governance" href="http://www.theiia.org/bookstore/product/it-auditing-it-governance-1273.cfm" target="_blank"><em>IT Auditing: IT Governance</em></a>. Mission Viejo: Pleier. CD-ROM.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/risk-management-is-it-just-another-set-of-business-buzzwords-part-vii/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Risk Management: Is it just another set of business buzzwords? – Part VI</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/risk-management-is-it-just-another-set-of-business-buzzwords-part-vi/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/risk-management-is-it-just-another-set-of-business-buzzwords-part-vi/#comments</comments>
		<pubDate>Thu, 14 Mar 2013 01:10:44 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[Administrative Control]]></category>
		<category><![CDATA[Asset Management]]></category>
		<category><![CDATA[Business Continuity]]></category>
		<category><![CDATA[Continuity Management]]></category>
		<category><![CDATA[Crisis Management]]></category>
		<category><![CDATA[Decision Making]]></category>
		<category><![CDATA[Due Care]]></category>
		<category><![CDATA[Due Diligence]]></category>
		<category><![CDATA[Enterprise Governance]]></category>
		<category><![CDATA[Event Management]]></category>
		<category><![CDATA[Incident Management]]></category>
		<category><![CDATA[Information Technology]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[IT Management]]></category>
		<category><![CDATA[Management Information System]]></category>
		<category><![CDATA[Operating Style]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Threat Management]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=1894</guid>
		<description><![CDATA[Controlling and monitoring activities attempting to ensure acceptable risk responses include: Policies Directives Standards Procedures Rules Strategically; policies are definite courses or methods of action selected by management from alternatives, considering the environment, to guide as well as determine present and future decisions.  For example, an entity’s IT governance related policy may require IT management [...]]]></description>
				<content:encoded><![CDATA[<p>Controlling and monitoring activities attempting to ensure acceptable risk responses include:</p>
<ul>
<li>Policies</li>
<li>Directives</li>
<li>Standards</li>
<li>Procedures</li>
<li>Rules</li>
</ul>
<p>Strategically; <strong>policies</strong> are definite courses or methods of action selected by management from alternatives, considering the environment, to guide as well as determine present and future decisions.  For example, an entity’s IT governance related policy may require IT management obtain signed Service Level Agreements (SLAs) for all deployed systems.</p>
<p><strong>Directives</strong> serve or intend to guide, govern, or influence actions or goals.  Furthermore, directives should be considered orders or instructions.  When activated, entity proxy directives can be interpreted as conveying fiduciary requirements to the assignee.  Internal or external central authorities may issue directives as well as individuals.  For example, an external aviation agency may direct aircraft operators to carefully inspect a particular airplane wing.  Internally, directives are usually documented in memorandums and reflect matters requiring immediate attention.  Directives should receive the same due diligence as policies and procedures.</p>
<p>Source</p>
<p>Davis, Robert E. (2011). <em>Assuring IT Governance</em>. Available from <a href="http://www.amazon.com/Assuring-Governance-Assurance-Services-ebook/dp/B0058P58E0">http://www.amazon.com/Assuring-Governance-Assurance-Services-ebook/dp/B0058P58E0</a> and <a href="http://www.smashwords.com/books/view/70359">http://www.smashwords.com/books/view/70359</a></p>
<p>Davis, Robert E. (2006). <a title="IT Auditing: IT Governance" href="http://www.theiia.org/bookstore/product/it-auditing-it-governance-1273.cfm" target="_blank"><em>IT Auditing: IT Governance</em></a>. Mission Viejo: Pleier. CD-ROM.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/risk-management-is-it-just-another-set-of-business-buzzwords-part-vi/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Risk Management: Is it just another set of business buzzwords? – Part V</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/risk-management-is-it-just-another-set-of-business-buzzwords-part-v/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/risk-management-is-it-just-another-set-of-business-buzzwords-part-v/#comments</comments>
		<pubDate>Fri, 08 Mar 2013 22:41:01 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[Administrative Control]]></category>
		<category><![CDATA[Asset Management]]></category>
		<category><![CDATA[Business Continuity]]></category>
		<category><![CDATA[Continuity Management]]></category>
		<category><![CDATA[Crisis Management]]></category>
		<category><![CDATA[Decision Making]]></category>
		<category><![CDATA[Due Care]]></category>
		<category><![CDATA[Due Diligence]]></category>
		<category><![CDATA[Enterprise Governance]]></category>
		<category><![CDATA[Event Management]]></category>
		<category><![CDATA[Incident Management]]></category>
		<category><![CDATA[Information Technology]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[IT Management]]></category>
		<category><![CDATA[Management Information System]]></category>
		<category><![CDATA[Operating Style]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Threat Management]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=1818</guid>
		<description><![CDATA[Usually, IT risk analysis has four primary goals: Identifying assets and their associated values Identifying vulnerabilities and threats Quantifying the probability and business impact of potential threats Providing an economic balance between threat impact and countermeasure cost Normally, the IT Threat Assessment precedes the IT Vulnerability Assessment. However, Vulnerability Analysis results can identify relevant threats [...]]]></description>
				<content:encoded><![CDATA[<p>Usually, IT risk analysis has four primary goals:</p>
<ul>
<li>Identifying assets and their associated values</li>
<li>Identifying vulnerabilities and threats</li>
<li>Quantifying the probability and business impact of potential threats</li>
<li>Providing an economic balance between threat impact and countermeasure cost</li>
</ul>
<p>Normally, the IT Threat Assessment precedes the IT Vulnerability Assessment. However, Vulnerability Analysis results can identify relevant threats and Threat or Opportunity Analysis results can identify relevant vulnerabilities. The Association of Insurance and Risk Managers, the Association of Local Authority Risk Managers, and the Institute of Risk Management <a title="Risk Management: Is it just another set of business buzzwords? – Part II" href="http://itknowledgeexchange.techtarget.com/it-governance/risk-management-is-it-just-another-set-of-business-buzzwords-part-ii/" target="_blank">business risk model</a> categories can be mapped into IT risk analysis. For example, usually risk identification, description, and estimation are respectively included as asset valuation, action plan, and risk evaluation sub-processes.</p>
<p>Source</p>
<p>Davis, Robert E. (2011). <em>Assuring IT Governance</em>. Available from <a href="http://www.amazon.com/Assuring-Governance-Assurance-Services-ebook/dp/B0058P58E0">http://www.amazon.com/Assuring-Governance-Assurance-Services-ebook/dp/B0058P58E0</a> and <a href="http://www.smashwords.com/books/view/70359">http://www.smashwords.com/books/view/70359</a></p>
<p>Davis, Robert E. (2006). <a title="IT Auditing: IT Governance" href="http://www.theiia.org/bookstore/product/it-auditing-it-governance-1273.cfm" target="_blank"><em>IT Auditing: IT Governance</em></a>. Mission Viejo: Pleier. CD-ROM.</p>
<p>&nbsp;</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/risk-management-is-it-just-another-set-of-business-buzzwords-part-v/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Risk Management: Is it just another set of business buzzwords? – Part IV</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/risk-management-is-it-just-another-set-of-business-buzzwords-part-iv/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/risk-management-is-it-just-another-set-of-business-buzzwords-part-iv/#comments</comments>
		<pubDate>Thu, 07 Mar 2013 01:54:36 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[Administrative Control]]></category>
		<category><![CDATA[Asset Management]]></category>
		<category><![CDATA[Business Continuity]]></category>
		<category><![CDATA[Continuity Management]]></category>
		<category><![CDATA[Crisis Management]]></category>
		<category><![CDATA[Decision Making]]></category>
		<category><![CDATA[Due Care]]></category>
		<category><![CDATA[Due Diligence]]></category>
		<category><![CDATA[Enterprise Governance]]></category>
		<category><![CDATA[Event Management]]></category>
		<category><![CDATA[Incident Management]]></category>
		<category><![CDATA[Information Technology]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[IT Management]]></category>
		<category><![CDATA[Management Information System]]></category>
		<category><![CDATA[Operating Style]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Threat Management]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=1881</guid>
		<description><![CDATA[The risk management process introduces a systematic approach for identifying, assessing, and reducing risks as well as maintaining defined acceptable risk levels.  An IT risk assessment should be considered a key risk management practice area.  When management institutionalizes an IT governance risk assessment methodology, quantitative and/or qualitative factors effecting business processes should be considered, evaluated, [...]]]></description>
				<content:encoded><![CDATA[<p>The risk management process introduces a systematic approach for identifying, assessing, and reducing risks as well as maintaining defined acceptable risk levels.  An IT risk assessment should be considered a key risk management practice area.  When management institutionalizes an IT governance risk assessment methodology, quantitative and/or qualitative factors effecting business processes should be considered, evaluated, and documented to enable suitable event responses.  Management’s IT processes risk assessment determines IT potential opportunity cost and control implementation criticality.  Quantitative risk calculations include:</p>
<ul>
<li>Exposure Factor = Percentage of asset lost caused by identified risk</li>
<li>Single Loss Expectancy (SLE) = Asset Value X Exposure Factor</li>
<li>Annualized Rate of Occurrence (ARO) = Estimated frequency a threat will occur within a year</li>
<li>Annualized Loss Expectancy (ALE) = SLE X ARO</li>
<li>Safeguard Cost/Benefit Analysis = (ALE before implementing safeguard) – (ALE after implementing safeguard) – (annual cost of safeguard)</li>
</ul>
<p>Source</p>
<p>Davis, Robert E. (2011). <em>Assuring IT Governance</em>. Available from <a href="http://www.amazon.com/Assuring-Governance-Assurance-Services-ebook/dp/B0058P58E0">http://www.amazon.com/Assuring-Governance-Assurance-Services-ebook/dp/B0058P58E0</a> and <a href="http://www.smashwords.com/books/view/70359">http://www.smashwords.com/books/view/70359</a></p>
<p>Davis, Robert E. (2006). <a title="IT Auditing: IT Governance" href="http://www.theiia.org/bookstore/product/it-auditing-it-governance-1273.cfm" target="_blank"><em>IT Auditing: IT Governance</em></a>. Mission Viejo: Pleier. CD-ROM.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/risk-management-is-it-just-another-set-of-business-buzzwords-part-iv/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Risk Management: Is it just another set of business buzzwords? – Part III</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/risk-management-is-it-just-another-set-of-business-buzzwords-part-iii/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/risk-management-is-it-just-another-set-of-business-buzzwords-part-iii/#comments</comments>
		<pubDate>Sat, 02 Mar 2013 16:38:44 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[Administrative Control]]></category>
		<category><![CDATA[Asset Management]]></category>
		<category><![CDATA[Business Continuity]]></category>
		<category><![CDATA[Continuity Management]]></category>
		<category><![CDATA[Crisis Management]]></category>
		<category><![CDATA[Decision Making]]></category>
		<category><![CDATA[Due Care]]></category>
		<category><![CDATA[Due Diligence]]></category>
		<category><![CDATA[Enterprise Governance]]></category>
		<category><![CDATA[Event Management]]></category>
		<category><![CDATA[Incident Management]]></category>
		<category><![CDATA[Information Technology]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[IT Management]]></category>
		<category><![CDATA[Management Information System]]></category>
		<category><![CDATA[Operating Style]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Threat Management]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=1874</guid>
		<description><![CDATA[Similar to business risk management, IT risk management is a continuous process that should be interlaced into the fabric of an entity.  IT risks directly impact an entity’s ability to provide goods and/or services at an acceptable price.  Inherently, computer hardware and software as well as personnel present potential risks to an entity achieving business [...]]]></description>
				<content:encoded><![CDATA[<p>Similar to business risk management, IT risk management is a continuous process that should be interlaced into the fabric of an entity.  IT risks directly impact an entity’s ability to provide goods and/or services at an acceptable price.  Inherently, computer hardware and software as well as personnel present potential risks to an entity achieving business objectives.</p>
<p>Through appropriate management, risks can be accepted, reduced, or transferred; however, IT related risk can never be completely eliminated.  Minimally, IT governance risk management should address strategic alignment, value delivery, resource management, and performance measurement.  Depending on the circumstances, entity and IT governance domain characteristics may overlap or have distinctiveness, yet IT controls continuity and stability can be sustained even when governance domain characteristics are mutually inclusive.</p>
<p>Source</p>
<p>Davis, Robert E. (2011). <em>Assuring IT Governance</em>. Available from <a href="http://www.amazon.com/Assuring-Governance-Assurance-Services-ebook/dp/B0058P58E0">http://www.amazon.com/Assuring-Governance-Assurance-Services-ebook/dp/B0058P58E0</a> and <a href="http://www.smashwords.com/books/view/70359">http://www.smashwords.com/books/view/70359</a></p>
<p>Davis, Robert E. (2006). <a title="IT Auditing: IT Governance" href="http://www.theiia.org/bookstore/product/it-auditing-it-governance-1273.cfm" target="_blank"><em>IT Auditing: IT Governance</em></a>. Mission Viejo: Pleier. CD-ROM.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/risk-management-is-it-just-another-set-of-business-buzzwords-part-iii/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Risk Management: Is it just another set of business buzzwords? – Part II</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/risk-management-is-it-just-another-set-of-business-buzzwords-part-ii/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/risk-management-is-it-just-another-set-of-business-buzzwords-part-ii/#comments</comments>
		<pubDate>Thu, 28 Feb 2013 02:50:25 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[Administrative Control]]></category>
		<category><![CDATA[Asset Management]]></category>
		<category><![CDATA[Business Continuity]]></category>
		<category><![CDATA[Continuity Management]]></category>
		<category><![CDATA[Crisis Management]]></category>
		<category><![CDATA[Decision Making]]></category>
		<category><![CDATA[Due Care]]></category>
		<category><![CDATA[Due Diligence]]></category>
		<category><![CDATA[Enterprise Governance]]></category>
		<category><![CDATA[Event Management]]></category>
		<category><![CDATA[Incident Management]]></category>
		<category><![CDATA[Information Technology]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[IT Management]]></category>
		<category><![CDATA[Management System]]></category>
		<category><![CDATA[Operating Style]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Threat Management]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=1867</guid>
		<description><![CDATA[An entity’s business risk management framework should be a strategic axial enabled to accept diverse strategy spokes. Proactively, business risk management should represent the process whereby an entity methodically addresses risks attached to activities with the objective of achieving sustained benefit within each activity and across the activities portfolio. Through project collaboration the Association of [...]]]></description>
				<content:encoded><![CDATA[<p>An entity’s business risk management framework should be a strategic axial enabled to accept diverse strategy spokes. Proactively, business risk management should represent the process whereby an entity methodically addresses risks attached to activities with the objective of achieving sustained benefit within each activity and across the activities portfolio.</p>
<p>Through project collaboration the Association of Insurance and Risk Managers, the Association of Local Authority Risk Managers, and the Institute of Risk Management promote the following risk management process:</p>
<p>1. Identify Strategic Objectives</p>
<p>2. Perform Risk Assessment</p>
<p>2.1 Risk Analysis</p>
<p>2.1.1 Risk Identification</p>
<p>2.1.2 Risk Description</p>
<p>2.1.3 Risk Estimation</p>
<p>2.2 Risk Evaluation</p>
<p>3. Provide Risk Reporting</p>
<p>4. Decision (determine risk appetite)</p>
<p>5. Document Risk Treatment</p>
<p>6. Provide Residual Risk Reporting</p>
<p>7. Perform Monitoring</p>
<p>Source</p>
<p>Davis, Robert E. (2011). <em>Assuring IT Governance</em>. Available from <a href="http://www.amazon.com/Assuring-Governance-Assurance-Services-ebook/dp/B0058P58E0">http://www.amazon.com/Assuring-Governance-Assurance-Services-ebook/dp/B0058P58E0</a> and <a href="http://www.smashwords.com/books/view/70359">http://www.smashwords.com/books/view/70359</a></p>
<p>Davis, Robert E. (2006). <a title="IT Auditing: IT Governance" href="http://www.theiia.org/bookstore/product/it-auditing-it-governance-1273.cfm" target="_blank"><em>IT Auditing: IT Governance</em></a>. Mission Viejo: Pleier. CD-ROM.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/risk-management-is-it-just-another-set-of-business-buzzwords-part-ii/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Risk Management: Is it just another set of business buzzwords? &#8211; Part I</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/risk-management-is-it-just-another-set-of-business-buzzwords-part-i/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/risk-management-is-it-just-another-set-of-business-buzzwords-part-i/#comments</comments>
		<pubDate>Sat, 23 Feb 2013 18:44:08 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[Administrative Control]]></category>
		<category><![CDATA[Asset Management]]></category>
		<category><![CDATA[Business Continuity]]></category>
		<category><![CDATA[Continuity Management]]></category>
		<category><![CDATA[Crisis Management]]></category>
		<category><![CDATA[Decision Making]]></category>
		<category><![CDATA[Due Care]]></category>
		<category><![CDATA[Due Diligence]]></category>
		<category><![CDATA[Enterprise Governance]]></category>
		<category><![CDATA[Event Management]]></category>
		<category><![CDATA[Incident Management]]></category>
		<category><![CDATA[Information Technology]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[IT Management]]></category>
		<category><![CDATA[Management System]]></category>
		<category><![CDATA[Operating Style]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Threat Management]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=1857</guid>
		<description><![CDATA[Risk management is not an issue any ‘going concern’ should consider a platitude used to demonstrate effective leadership.  Those responsible for governance within an enterprise must be, without reservation, administrators dedicated to appropriately handling the risks that their organization encounters.  In particular, the risks associated with information and related technology must be comprehensively identified and [...]]]></description>
				<content:encoded><![CDATA[<p>Risk management is not an issue any ‘<a title="Investopedia - Definition of 'Going Concern'" href="http://www.investopedia.com/terms/g/goingconcern.asp" target="_blank">going concern</a>’ should consider a platitude used to demonstrate effective leadership.  Those responsible for governance within an enterprise must be, without reservation, administrators dedicated to appropriately handling the risks that their organization encounters.  In particular, the risks associated with information and related technology must be comprehensively identified and appropriately managed based on careful consideration of the impact and likelihood of the projected occurrence of detrimental events. It is in this arena that organizational risk management commonly fails to accurately portray the environmental landscape enabling resource optimization of initial investments and operational maintenance for IT.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/risk-management-is-it-just-another-set-of-business-buzzwords-part-i/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Are Organizations Potentially Falling Short?</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/are-organizations-potentially-falling-short/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/are-organizations-potentially-falling-short/#comments</comments>
		<pubDate>Tue, 07 Aug 2012 17:48:35 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[Accountability]]></category>
		<category><![CDATA[Accounting]]></category>
		<category><![CDATA[Application Portfolio Management]]></category>
		<category><![CDATA[Asset Management]]></category>
		<category><![CDATA[Audit Assurance]]></category>
		<category><![CDATA[Audit Committee]]></category>
		<category><![CDATA[Certified Information Systems Auditor]]></category>
		<category><![CDATA[Change Control]]></category>
		<category><![CDATA[Change Management]]></category>
		<category><![CDATA[Control Processes]]></category>
		<category><![CDATA[Decision Making]]></category>
		<category><![CDATA[Enterprise Governance]]></category>
		<category><![CDATA[ERP]]></category>
		<category><![CDATA[Fiduciary Responsibility]]></category>
		<category><![CDATA[Governance Tree]]></category>
		<category><![CDATA[IT Governanace]]></category>
		<category><![CDATA[Life Cycle Management]]></category>
		<category><![CDATA[Organizational Structure]]></category>
		<category><![CDATA[Project Management]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Value Delivery]]></category>
		<category><![CDATA[Financial]]></category>
		<category><![CDATA[Profits]]></category>
		<category><![CDATA[Reputation]]></category>
		<category><![CDATA[Trading]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=1394</guid>
		<description><![CDATA[Current events posted by various news outlets, including Fox News, the Wall Street Journal, Forbes and Yahoo.com, concerning Knight Capital’s financial debacle, present some very serious allegations regarding managerial due diligence during system development lifecycles.  In this case, the cost to the already troubled firm is an estimated $440,000,000.00 USD.  An amount no financial-based institution [...]]]></description>
				<content:encoded><![CDATA[<p>Current events posted by various news outlets, including Fox News, the Wall Street Journal, Forbes and Yahoo.com, concerning <a href="http://www.knight.com/">Knight Capital</a>’s financial debacle, present some very serious allegations regarding managerial due diligence during system development lifecycles.  In this case, the cost to the already troubled firm is an estimated $440,000,000.00 USD.  An amount no financial-based institution can classify as immaterial.</p>
<p>Undoubtedly, an individual and/or group authorized activation of this critical new application.  Yet, it appears adequate precautions, such as application processing testing, were not performed either prior to deployment, during implementation, or after installation by the project team.</p>
<p>Considering, <em><a title="Academia.edu - Robert E. Davis" href="http://temple.academia.edu/RobertEDavis/Books" target="_blank"> as computing power has advanced, entities have become increasingly dependent on technology to carry out their operational requirements and to collect, process, maintain, and report essential data.  This reliance on electronically encoded data and on the systems that affect managerial decisions are a major concern of audit professionals.  Consequently, Information Technology (IT) auditors examine the adequacy of controls in information systems and related operations to assure effectiveness and efficiency in business processes.  In addition, among other assurance services, IT auditors evaluate the reliability of computer generated data supporting financial statements and analyze specific programs and their processing results</a>.</em>  Thus, my question regarding the circumstances that produced this extraordinary financial loss is: <a title="Yahoo! Finance - Insight: Knight's Joyce gets reprieve but new owners want answers" href="http://finance.yahoo.com/news/insight-knights-joyce-gets-reprieve-172947522.html?goback=.nmp_%2A1_%2A1_%2A1_%2A1_%2A1_%2A1_%2A1_%2A1_%2A1.gna_4173763.gde_4173763_member_145168632" target="_blank">Did management assign an IT auditor to the software project team?</a></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/are-organizations-potentially-falling-short/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Not-for-profit Risk Management &#8211; Part VIII</title>
		<link>http://itknowledgeexchange.techtarget.com/it-governance/not-for-profit-risk-management-part-viii/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-governance/not-for-profit-risk-management-part-viii/#comments</comments>
		<pubDate>Tue, 27 Jul 2010 15:28:43 +0000</pubDate>
		<dc:creator>Robert Davis</dc:creator>
				<category><![CDATA[COBIT]]></category>
		<category><![CDATA[Educational Institutions]]></category>
		<category><![CDATA[Enterprise Governance]]></category>
		<category><![CDATA[Entity Governance]]></category>
		<category><![CDATA[Governance Tree]]></category>
		<category><![CDATA[Government Agencies]]></category>
		<category><![CDATA[ICT]]></category>
		<category><![CDATA[IT Architecture]]></category>
		<category><![CDATA[IT Service Management]]></category>
		<category><![CDATA[ITG]]></category>
		<category><![CDATA[ITSM]]></category>
		<category><![CDATA[Performance Measurement]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Risk Tolerance]]></category>
		<category><![CDATA[Strategic Planning]]></category>
		<category><![CDATA[Value Delivery]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-governance/?p=648</guid>
		<description><![CDATA[IT risk management is important to delivering an entity’s strategic plan.]]></description>
				<content:encoded><![CDATA[<p>Deploying Enterprise Governance bilaterally connected to <a href="http://www.theiia.org/bookstore/product/it-auditing-it-governance-1273.cfm">IT Governance</a> enables management to focus on value creation drivers that move an entity forward and sustain proper as well as adequate controls.  <strong>IT risk management</strong> is important to delivering an entity’s strategic plan.  In totality, the adopted IT risk management framework can provide structures, methodologies, procedures, and definitions that an entity has chosen to utilize for deploying risk management processes.  At the detail level, process models can be adopted by IT to support risk management, thus providing a powerful tool for appropriate IT service management consistent with the entity’s strategic plan.  Process and service management are certainly closely related to IT governance.  Yet, without adequate risk management, IT governance is in jeopardy of not meeting expected <strong>value delivery</strong> benefits.</p>
<p>&#8220;<em>View Part I of the Not-for-profit Risk Management series <a href="http://itknowledgeexchange.techtarget.com/it-governance/not-for-profit-risk-management-part-i/">here</a>&#8220;</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-governance/not-for-profit-risk-management-part-viii/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
