Centralize your risk response – the need for a Risk Operations Center



In The Boscombe Valley Mystery by Arthur Conan Doyle, Sherlock Holmes comments that, “There is nothing more deceptive than an obvious fact.” When it comes to risk, it’s obvious that companies should want to remove or reduce risk as much as possible. But the process – how you actually carry out the actions to eliminate risk, and how you collaborate to make that risk reduction work across the business – is not obvious. To improve this, we have to look at how we consider risk across the whole organization. This requires a Risk Operations Center, or ROC.

Richard Seiersen

Chief Risk Technology Officer for Qualys.

What’s in a name?

When CISOs hear the phrase “Risk Operations Center” they invariably ask, “How is a ROC different from a Security Operations Center?” Let’s begin answering this question with a concise definition for what a ROC aims to achieve: A ROC orchestrates risk elimination.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *

Site Statistics
  • Today's visitors: 103
  • Today's page views: : 106
  • Total visitors : 96,538
  • Total page views: 107,993

Powered By WordPress | Joblook