Developing a Common Language About IT Risk Management
Name
Common Language WestermanHunter2.pdf
Size
314.01 KB
Format
Adobe PDF
Checksum (MD5)
4fac471963f2fede414e3f7a5252415e
Author(s) •
Westerman, George
Hunter, Richard
Date Issued
June 1, 2009
Publisher
Alfred P. Sloan School of Management, Massachusetts Institute of Technology; Cambridge, MA
Series/Report no.
MIT Sloan School of Management Working Paper;4933-11
CISR Working Paper;377
Abstract
Although IT risks can have wide-ranging business consequences, few executives feel comfortable discussing IT risk management. It doesn’t have to be this way. Executive-level tradeoffs around IT risk are managerial, not technical. The Four
A Framework of Availability, Access, Accuracy, and Agility risks provides a common language that business and IT managers can use to manage IT risks
without getting bogged down in technical complexity. Then you can build a risk
management capability—by improving the IT foundation, installing a risk
governance process, and creating a risk aware culture—that increases the returns from your IT risk management investments.
Subjects
IT risk
Non-IT executive viewpoint
IT governance
alignment
oversight
risk aware culture
architecture
business continuity
security
agility
regulatory compliance
privacy
Terms of Use
An error occurred on the license name.
Persistent DSpace Link