|
Sections |
| Title | Starting Page | Number of Pages |
|---|
| Contents â?? December 2008
Section 1: Management Summary 9
1.1 Management Summary 11
Section 2: Introduction 15
2.1 Report Objectives and Structure 17
2.2 Governance, Risk, and Compliance Strategy 19
2.3 IT Vulnerabilities 23
Section 3: Business Issues and | 0 | 1 |
| Contents – December 2008 | 0 | 1 |
| Section 1: Management Summary | 9 | 6 |
| 1.1 Management Summary | 11 | 4 |
| Section 1: Management Summary 9 | 0 | 1 |
| 1.1 Management Summary 11 | 0 | 1 |
| Section 2: Introduction | 15 | 12 |
| 2.1 Report Objectives and Structure | 17 | 2 |
| Section 2: Introduction 15 | 0 | 1 |
| 2.1 Report Objectives and Structure 17 | 0 | 1 |
| 2.2 Governance, Risk, and Compliance Strategy | 19 | 4 |
| 2.3 IT Vulnerabilities | 23 | 4 |
| 2.2 Governance, Risk, and Compliance Strategy 19 | 0 | 1 |
| 2.3 IT Vulnerabilities 23 | 0 | 1 |
| Section 3: Business Issues and Drivers | 27 | 18 |
| 3.1 Business Risk Profile | 29 | 3 |
| Section 3: Business Issues and Drivers 27 | 0 | 1 |
| 3.1 Business Risk Profile 29 | 0 | 1 |
| 3.2 Business Implications of IT Risk | 32 | 5 |
| 3.3 Compliance and Security Requirements | 37 | 4 |
| 3.2 Business Implications of IT Risk 32 | 0 | 1 |
| 3.3 Compliance and Security Requirements 37 | 0 | 1 |
| 3.4 Understanding the Benefits | 41 | 4 |
| Section 4: IT Risk Management Strategies | 45 | 16 |
| 3.4 Understanding the Benefits 41 | 0 | 1 |
| Section 4: IT Risk Management Strategies 45 | 0 | 1 |
| 4.1 Planning an IT Risk Management Strategy | 47 | 4 |
| 4.2 Roles and Responsibilities | 51 | 3 |
| 4.1 Planning an IT Risk Management Strategy 47 | 0 | 1 |
| 4.2 Roles and Responsibilities 51 | 0 | 1 |
| 4.3 Gauging IT Risk Maturity | 54 | 3 |
| 4.4 Supporting Strategies | 57 | 4 |
| 4.3 Gauging IT Risk Maturity 54 | 0 | 1 |
| 4.4 Supporting Strategies 57 | 0 | 1 |
| Section 5: IT Risk Management Lifecycle | 61 | 16 |
| 5.1 IT Risk Assessment | 63 | 3 |
| Section 5: IT Risk Management Lifecycle 61 | 0 | 1 |
| 5.1 IT Risk Assessment 63 | 0 | 1 |
| 5.2 IT Risk Mitigation | 66 | 5 |
| 5.3 IT Risk Management Framework | 71 | 6 |
| 5.2 IT Risk Mitigation 66 | 0 | 1 |
| 5.3 IT Risk Management Framework 71 | 0 | 1 |
| Section 6: Business Continuity | 77 | 18 |
| 6.1 Business Continuity Strategy and Planning | 79 | 3 |
| Section 6: Business Continuity 77 | 0 | 1 |
| 6.1 Business Continuity Strategy and Planning 79 | 0 | 1 |
| 6.2 Planning for Business Continuity | 82 | 5 |
| 6.3 Organisational and Infrastructure Resilience | 87 | 3 |
| 6.2 Planning for Business Continuity 82 | 0 | 1 |
| 6.3 Organisational and Infrastructure Resilience 87 | 0 | 1 |
| 6.4 Impact of External Services | 90 | 5 |
| Section 7: Security | 95 | 16 |
| 6.4 Impact of External Services 90 | 0 | 1 |
| Section 7: Security 95 | 0 | 1 |
| 7.1 Security Management and Compliance | 97 | 3 |
| 7.2 Protecting Against Threats | 100 | 4 |
| 7.1 Security Management and Compliance 97 | 0 | 1 |
| 7.2 Protecting Against Threats 100 | 0 | 1 |
| 7.3 Mitigating Identity and Access Risk | 104 | 3 |
| 7.4 Information Risk and Data Loss Prevention | 107 | 4 |
| 7.3 Mitigating Identity and Access Risk 104 | 0 | 1 |
| 7.4 Information Risk and Data Loss Prevention 107 | 0 | 1 |
| Section 8: Project Risk | 111 | 18 |
| 8.1 Managing the Project Portfolio | 113 | 3 |
| Section 8: Project Risk 111 | 0 | 1 |
| 8.1 Managing the Project Portfolio 113 | 0 | 1 |
| 8.2 Methods for Assessing Project Risk | 116 | 4 |
| 8.3 Managing Project Delivery Risk | 120 | 5 |
| 8.2 Methods for Assessing Project Risk 116 | 0 | 1 |
| 8.3 Managing Project Delivery Risk 120 | 0 | 1 |
| 8.4 Evaluating Project Benefit Risk | 125 | 4 |
| Section 9: Market Analysis | 129 | 14 |
| 8.4 Evaluating Project Benefit Risk 125 | 0 | 1 |
| Section 9: Market Analysis 129 | 0 | 1 |
| 9.1 IT Risk and the SME | 131 | 3 |
| 9.2 Supporting Technologies | 134 | 5 |
| 9.1 IT Risk and the SME 131 | 0 | 1 |
| 9.2 Supporting Technologies 134 | 0 | 1 |
| 9.3 IT Risk Functionality Within Management Suites | 139 | 4 |
| Section 10: Standards and Methodologies | 143 | 20 |
| 9.3 IT Risk Functionality Within Management Suites 139 | 0 | 1 |
| Section 10: Standards and Methodologies 143 | 0 | 1 |
| 10.1 Standards and Methodologies Relevance Matrix | 145 | 1 |
| 10.2 Standards and Methods Consolidated | 146 | 17 |
| 10.1 Standards and Methodologies Relevance Matrix 145 | 0 | 1 |
| 10.2 Standards and Methods Consolidated 146 | 0 | 1 |
| Section 11: Vendor Profiles | 163 | 24 |
| Agiliance | 165 | 1 |
| Section 11: Vendor Profiles 163 | 0 | 1 |
| Agiliance 165 | 0 | 1 |
| Archer Technologies | 166 | 1 |
| Axentis | 167 | 1 |
| Archer Technologies 166 | 0 | 1 |
| Axentis 167 | 0 | 1 |
| BMC | 168 | 1 |
| Brabeion Software | 169 | 1 |
| BMC 168 | 0 | 1 |
| Brabeion Software 169 | 0 | 1 |
| BWise | 170 | 1 |
| CA | 171 | 1 |
| BWise 170 | 0 | 1 |
| CA 171 | 0 | 1 |
| eIQnetworks | 172 | 1 |
| HP | 173 | 1 |
| eIQnetworks 172 | 0 | 1 |
| HP 173 | 0 | 1 |
| IBM | 174 | 2 |
| MEGA | 176 | 1 |
| IBM 174 | 0 | 1 |
| MEGA 176 | 0 | 1 |
| Methodware | 177 | 1 |
| Modulo | 177 | 2 |
| Methodware 177 | 0 | 1 |
| Modulo 177 | 0 | 1 |
| NetIQ | 179 | 1 |
| OpenPages | 180 | 1 |
| NetIQ 179 | 0 | 1 |
| OpenPages 180 | 0 | 1 |
| Oracle | 181 | 1 |
| Paisley | 182 | 1 |
| Oracle 181 | 0 | 1 |
| Paisley 182 | 0 | 1 |
| Relational Security | 183 | 1 |
| Symantec | 184 | 1 |
| Relational Security 183 | 0 | 1 |
| Symantec 184 | 0 | 1 |
| Tripwire | 185 | 2 |
| Section 12: Glossary | 187 | 14 |
| Tripwire 185 | 0 | 1 |
| Section 12: Glossary 187 | 0 | 1 |