<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://www.communities.hp.com/online/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Archie Reed’s Secure Observations Blog : GRC identity management</title><link>http://www.communities.hp.com/online/blogs/reed/archive/tags/GRC+identity+management/default.aspx</link><description>Tags: GRC identity management</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP1 (Build: 31106.3070)</generator><item><title>Cloud Security – HP’s CEO finds cloud computing – vague, unsecure, what?</title><link>http://www.communities.hp.com/online/blogs/reed/archive/2009/10/20/cloud-security-hp-s-ceo-finds-cloud-computing-vague-unsecure-what.aspx</link><pubDate>Tue, 20 Oct 2009 23:01:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:117217</guid><dc:creator>ArchieReed</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.communities.hp.com/online/blogs/reed/rsscomments.aspx?PostID=117217</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.communities.hp.com/online/blogs/reed/commentapi.aspx?PostID=117217</wfw:comment><comments>http://www.communities.hp.com/online/blogs/reed/archive/2009/10/20/cloud-security-hp-s-ceo-finds-cloud-computing-vague-unsecure-what.aspx#comments</comments><description>HP&amp;#39;s CEO, Mark Hurd, took the stage today as a keynote speaker at Gartner&amp;#39;s Symposium . Out of the gate we see the headlines such as &amp;quot; HP&amp;#39;s Hurd dings cloud computing, IBM &amp;quot; (CNET) and &amp;quot; HP&amp;#39;s Hurd: Cloud Computing Has its...(&lt;a href="http://www.communities.hp.com/online/blogs/reed/archive/2009/10/20/cloud-security-hp-s-ceo-finds-cloud-computing-vague-unsecure-what.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=117217" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/reed/archive/tags/GRC+identity+management/default.aspx">GRC identity management</category><category domain="http://www.communities.hp.com/online/blogs/reed/archive/tags/security/default.aspx">security</category><category domain="http://www.communities.hp.com/online/blogs/reed/archive/tags/cloud/default.aspx">cloud</category><category domain="http://www.communities.hp.com/online/blogs/reed/archive/tags/GRC/default.aspx">GRC</category></item><item><title>"Just say no to 'GRC'" - say what?</title><link>http://www.communities.hp.com/online/blogs/reed/archive/2008/07/11/quot-just-say-no-to-grc-quot-say-what.aspx</link><pubDate>Fri, 11 Jul 2008 16:48:00 GMT</pubDate><guid isPermaLink="false">964d1d0f-bea0-4201-a2aa-8aa369a35a46:83730</guid><dc:creator>ArchieReed</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.communities.hp.com/online/blogs/reed/rsscomments.aspx?PostID=83730</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.communities.hp.com/online/blogs/reed/commentapi.aspx?PostID=83730</wfw:comment><comments>http://www.communities.hp.com/online/blogs/reed/archive/2008/07/11/quot-just-say-no-to-grc-quot-say-what.aspx#comments</comments><description>&lt;p&gt;Unfortunately due to a last minutes change in plans I did not make it to this years Catalyst Conference, so I am working my way through the slides online and chatting with those who did attend.&lt;/p&gt;
&lt;p&gt;One thing that caught my eye was Bob Blakley&amp;#39;s Thursday talk on &amp;quot;Governance, Risk [Management] and Compliance&amp;quot; - a four letter word as he describes it.&lt;/p&gt;
&lt;p&gt;This peaks my interest for several reasons based on the customers and industry pundits that I have spoken to... Bob postulates, ney, demands that you &amp;quot;Just say no to &amp;#39;GRC&amp;#39;&amp;quot; to which I say nay (to say no)!&lt;/p&gt;
&lt;p&gt;Why?&lt;/p&gt;
&lt;p&gt;I have a great deal of respect for Bob, and acknowledge that he would be talking to many more folks in the industry than I, and while this could well be flamebait, I do not agree with his premise... Bob stated that thinking of GRC as one big thing will confuse you - Semantics are important here so the words &amp;quot;one big thing&amp;quot; are important. I say this is simply a point where you need to carefully think about the requirements of each disciple in toto, however by not bringing them together as &amp;quot;one big thing&amp;quot; as a long term initiative, you will end up with disconnects across each of these disciplnes- taking your organization down anyway. Execs don&amp;#39;t tend to like that.&lt;/p&gt;
&lt;p&gt;Fundamentally the security (and identity management) industry has spent years trying to manage each of these disciplines/requirements individually, and found issues specifcially because we were not joining up and aligning these disciplines when rolling out solutions. Having a single app, or set of applications, that coaliesces the planning and delivery of these disciplines allows an organization to manage their GRC requirements better. The &amp;quot;seperate people are responsible for each discpline&amp;quot; discussion is a red herring if you end up with seperate teams and disconnected products.. &lt;/p&gt;
&lt;p&gt;I discssed this with a couple colleagues who consult every day on these things - we see the following:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;div&gt;Companies are generally doing really well (or much better depending on your perspective) at Compliance.&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;Companies are doing OK at Governance&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;Companies are concerned with Risk.&lt;/div&gt;&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;So we have a catch 22 if we believe what Bob has put forth.&lt;/p&gt;
&lt;p&gt;Companies NEED to link GRC together to manage governance, minimize risk, and ensure compliance.&lt;/p&gt;
&lt;p&gt;My view here is that while these MAY be considered as seperate disciplines and requirements per se, it would be a mistake to do so.&amp;nbsp;This may be the result of pontification, or even the reality that different people/departments inside an organizaton are repsonsible for different components of GRC... HOWEVER, it is critical to consider them like we do many linked items (eg security approaches such as CIA and PDR)!&lt;/p&gt;
&lt;p&gt;Bob does lay out a lot of great things here.in the middle - for example, Bob says that many risk management approaches are wrong. They take only one tack such as focus on maximizing gain rather than minimizing losses only, consider the portfolio, consider wildcards and build in transperancy. Interestingly this is what is wrong with the beginning and end of Bob&amp;#39;s overall thesis. By not linking GRC together (properly of course), you increase your risk.&lt;/p&gt;
&lt;p&gt;A loss in any part of GRC systematicaly and dramitcally affects the other - pick you analogy as needed (pillars of support, legs of the stool, corners of the triangle).&lt;/p&gt;
&lt;p&gt;In the end Bob offers a number of recommendations including:&lt;/p&gt;
&lt;div class="O1" style="MARGIN-TOP:4.32pt;MARGIN-BOTTOM:0pt;MARGIN-LEFT:0.43in;VERTICAL-ALIGN:baseline;DIRECTION:ltr;TEXT-INDENT:-0.19in;unicode-bidi:embed;TEXT-ALIGN:left;language:en-US;mso-line-break-override:restrictions;punctuation-wrap:simple;"&gt;&lt;span style="FONT-SIZE:18pt;"&gt;&lt;span style="COLOR:#0073ba;mso-special-format:bullet;"&gt;•&lt;/span&gt;&lt;/span&gt;&lt;span style="FONT-SIZE:18pt;COLOR:black;FONT-FAMILY:&amp;#39;Arial Narrow&amp;#39;;language:en-US;mso-ascii-font-family:&amp;#39;Arial Narrow&amp;#39;;mso-color-index:1;"&gt;Don’t use “GRC” as a catch-all term&lt;/span&gt;&lt;/div&gt;
&lt;div class="O2" style="MARGIN-TOP:3.84pt;MARGIN-BOTTOM:0pt;MARGIN-LEFT:0.81in;VERTICAL-ALIGN:baseline;DIRECTION:ltr;TEXT-INDENT:-0.19in;unicode-bidi:embed;TEXT-ALIGN:left;language:en-US;mso-line-break-override:restrictions;punctuation-wrap:simple;"&gt;&lt;span style="FONT-SIZE:16pt;"&gt;&lt;span style="COLOR:gray;mso-special-format:bullet;mso-color-index:2;"&gt;•&lt;/span&gt;&lt;/span&gt;&lt;span style="FONT-SIZE:16pt;COLOR:black;FONT-FAMILY:&amp;#39;Arial Narrow&amp;#39;;language:en-US;mso-ascii-font-family:&amp;#39;Arial Narrow&amp;#39;;mso-color-index:1;"&gt;Say what you mean: governance, risk management, OR compliance&lt;/span&gt;&lt;/div&gt;
&lt;div class="O1" style="MARGIN-TOP:4.32pt;MARGIN-BOTTOM:0pt;MARGIN-LEFT:0.43in;VERTICAL-ALIGN:baseline;DIRECTION:ltr;TEXT-INDENT:-0.19in;unicode-bidi:embed;TEXT-ALIGN:left;language:en-US;mso-line-break-override:restrictions;punctuation-wrap:simple;"&gt;&lt;span style="FONT-SIZE:18pt;"&gt;&lt;span style="COLOR:#0073ba;mso-special-format:bullet;"&gt;•&lt;/span&gt;&lt;/span&gt;&lt;span style="FONT-SIZE:18pt;COLOR:black;FONT-FAMILY:&amp;#39;Arial Narrow&amp;#39;;language:en-US;mso-ascii-font-family:&amp;#39;Arial Narrow&amp;#39;;mso-color-index:1;"&gt;Think of governance as round-trip management&lt;/span&gt;&lt;/div&gt;
&lt;div class="O2" style="MARGIN-TOP:3.84pt;MARGIN-BOTTOM:0pt;MARGIN-LEFT:0.81in;VERTICAL-ALIGN:baseline;DIRECTION:ltr;TEXT-INDENT:-0.19in;unicode-bidi:embed;TEXT-ALIGN:left;language:en-US;mso-line-break-override:restrictions;punctuation-wrap:simple;"&gt;&lt;span style="FONT-SIZE:16pt;"&gt;&lt;span style="COLOR:gray;mso-special-format:bullet;mso-color-index:2;"&gt;•&lt;/span&gt;&lt;/span&gt;&lt;span style="FONT-SIZE:16pt;COLOR:black;FONT-FAMILY:&amp;#39;Arial Narrow&amp;#39;;language:en-US;mso-ascii-font-family:&amp;#39;Arial Narrow&amp;#39;;mso-color-index:1;"&gt;Do not think of it as something you can fix with tools&lt;/span&gt;&lt;/div&gt;
&lt;div class="O1" style="MARGIN-TOP:4.32pt;MARGIN-BOTTOM:0pt;MARGIN-LEFT:0.43in;VERTICAL-ALIGN:baseline;DIRECTION:ltr;TEXT-INDENT:-0.19in;unicode-bidi:embed;TEXT-ALIGN:left;language:en-US;mso-line-break-override:restrictions;punctuation-wrap:simple;"&gt;&lt;span style="FONT-SIZE:18pt;"&gt;&lt;span style="COLOR:#0073ba;mso-special-format:bullet;"&gt;•&lt;/span&gt;&lt;/span&gt;&lt;span style="FONT-SIZE:18pt;COLOR:black;FONT-FAMILY:&amp;#39;Arial Narrow&amp;#39;;language:en-US;mso-ascii-font-family:&amp;#39;Arial Narrow&amp;#39;;mso-color-index:1;"&gt;Measure risk management on the basis of value created&lt;/span&gt;&lt;/div&gt;
&lt;div class="O2" style="MARGIN-TOP:3.84pt;MARGIN-BOTTOM:0pt;MARGIN-LEFT:0.81in;VERTICAL-ALIGN:baseline;DIRECTION:ltr;TEXT-INDENT:-0.19in;unicode-bidi:embed;TEXT-ALIGN:left;language:en-US;mso-line-break-override:restrictions;punctuation-wrap:simple;"&gt;&lt;span style="FONT-SIZE:16pt;"&gt;&lt;span style="COLOR:gray;mso-special-format:bullet;mso-color-index:2;"&gt;•&lt;/span&gt;&lt;/span&gt;&lt;span style="FONT-SIZE:16pt;COLOR:black;FONT-FAMILY:&amp;#39;Arial Narrow&amp;#39;;language:en-US;mso-ascii-font-family:&amp;#39;Arial Narrow&amp;#39;;mso-color-index:1;"&gt;Not loss avoided&lt;/span&gt;&lt;/div&gt;
&lt;div class="O1" style="MARGIN-TOP:4.32pt;MARGIN-BOTTOM:0pt;MARGIN-LEFT:0.43in;VERTICAL-ALIGN:baseline;DIRECTION:ltr;TEXT-INDENT:-0.19in;unicode-bidi:embed;TEXT-ALIGN:left;language:en-US;mso-line-break-override:restrictions;punctuation-wrap:simple;"&gt;&lt;span style="FONT-SIZE:18pt;"&gt;&lt;span style="COLOR:#0073ba;mso-special-format:bullet;"&gt;•&lt;/span&gt;&lt;/span&gt;&lt;span style="FONT-SIZE:18pt;COLOR:black;FONT-FAMILY:&amp;#39;Arial Narrow&amp;#39;;language:en-US;mso-ascii-font-family:&amp;#39;Arial Narrow&amp;#39;;mso-color-index:1;"&gt;Measure compliance on the basis of loss avoided&lt;/span&gt;&lt;/div&gt;
&lt;div class="O2" style="MARGIN-TOP:3.84pt;MARGIN-BOTTOM:0pt;MARGIN-LEFT:0.81in;VERTICAL-ALIGN:baseline;DIRECTION:ltr;TEXT-INDENT:-0.19in;unicode-bidi:embed;TEXT-ALIGN:left;language:en-US;mso-line-break-override:restrictions;punctuation-wrap:simple;"&gt;&lt;span style="FONT-SIZE:16pt;"&gt;&lt;span style="COLOR:gray;mso-special-format:bullet;mso-color-index:2;"&gt;•&lt;/span&gt;&lt;/span&gt;&lt;span style="FONT-SIZE:16pt;COLOR:black;FONT-FAMILY:&amp;#39;Arial Narrow&amp;#39;;language:en-US;mso-ascii-font-family:&amp;#39;Arial Narrow&amp;#39;;mso-color-index:1;"&gt;Not liability avoided&lt;/span&gt;&lt;/div&gt;
&lt;p&gt;I agree, but the lead in for this set is based on the wrong premise.&lt;/p&gt;
&lt;p&gt;Going forward the requriements in each of these areas will become greater, as a result, the importance of these disciplines being aligned becomes much greater still - just say no, to saying no to GRC...&lt;/p&gt;
&lt;p&gt;Be smart, don&amp;#39;t buy what you don&amp;#39;t need.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/online/aggbug.aspx?PostID=83730" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/online/blogs/reed/archive/tags/GRC+identity+management/default.aspx">GRC identity management</category></item></channel></rss>