Branch topics LASER World of PHOTONICS World of Photonics Congress LASER World of PHOTONICS CHINA LASER World of PHOTONICS INDIA
HOME
INDUSTRY TOPICS
BUSINESS LIFE
Search in...
 EVENT SCHEDULE 
go
full text search
in/at
in/at
 only Highlights
on/at
from - to
 - 
 CONFERENCE PROGRAM 
go
Keyword
Search by topics
Search by conferences
 
:-) my.world-of-photonics.net
Username 
Password 
Password forgotten? 
Register now!
i All about my.world-of-photonics.net






Mercateo - der Megahändler für Geschäftskunden im Internet

print page recommend page  |   Deutsch
PRACTICE
MMI/ks
CIOs must manage IT risk as business risk

While IT has become increasingly central to business success, many enterprises have not adjusted their processes for IT decision making and risk management, according to Gartner, Inc. In addition, increased dependence on the smooth functioning of IT has amplified the business impact of IT risk incidents.

In the book “IT Risk :Turning Business Threats into Competitive Advantage”, published by Harvard Business School Press, Richard Hunter, group vice-president and Gartner fellow in Gartner Executive Programmes, and George Westerman, research scientist in the Center for Information Systems Research at the MIT Sloan School of Management, examine how IT risks directly impact business performance, and advise business executives on how they can manage IT risk as business risk with business consequences.

“IT risk has changed,” said Mr Hunter, who presented findings from the book during the Gartner IT Security Summit 2007, which is being held from 17-19 September in London, UK. “IT risk incidents harm constituencies within and outside companies. They damage corporate reputations and expose weaknesses in companies’ management teams. Most importantly, uncontrolled IT risk dampens an organisation’s ability to compete.”

He cited the examples of a failed software implementation at a pharmaceutical manufacturer that led to the company’s bankruptcy, a data theft at CardSystems Solutions that prompted the company’s two largest customers - Visa and Mastercard - to defect, and errors in a tax-credit management system at the UK Inland Revenue that led the organisation to pay out over £2 billion in erroneous tax credits.

“In many companies, it is difficult for business and IT people to exchange information about IT risks in a mutually meaningful way,” said Mr Hunter. “To make effective decisions about IT risk, business executives need to know what happens to the business when technology fails or underperforms. Furthermore, any IT risk must be understood in terms of its potential to affect all of the company objectives that are enabled by IT. IT risk is too important to be delegated entirely to the IT organisation.”

The authors defined IT risk as a threat to any of four interrelated business objectives:

  1. Business objective:Availability
    IT risk: Will a company’s IT systems and business processes continue running, and will they recover from interruptions?
  2. Business objective:Access
    IT risk: Do the right people in an organisation have access to the data and systems they need to do their jobs? Are the wrong people blocked from access to those data and systems?
  3. Business objective: Accuracy
    IT risk: Can a company’s IT systems be relied on to provide correct, timely, and complete information that meets the requirements of management, staff, customers, suppliers, and regulators?
  4. Business objective: Agility
    IT risk: Do the organisation’s IT systems possess the capability to change if the company acquires another firm, completes a major business process redesign, or launches a new product or service?

“No enterprise can be completely free of IT risk. Like any other risk, IT risk is something to be managed, not eliminated,” Mr Hunter said. “Management means making trade-offs between risk and return, between the perils a company can bear and the risks it would rather avoid. But until now, business managers have lacked the tools and disciplines to manage IT risk in these ways.”

Three disciplines that enterprises must master to manage IT risk effectively:

  • A solid foundation of IT assets, people, and supporting processes and controls that enable executives to manage the right risks in the right order.
  • A well-designed risk governance structure and process: integrating IT risk management into every business decision to identify, prioritise and track risks.
  • A risk-aware culture, nurtured from the top, that attunes people to the causes and solutions for IT risks and that increases vigilance across the organisation.

“These disciplines are complementary. Together, they aim to improve risk management capability and giving business and IT people a language to ensure that IT risks stay under control,” he added. “Enterprises should choose their focal discipline based on their culture, their circumstances and their capabilities, but ultimately they must be competent in all three.”

“The most dangerous risks are the ones that are never considered, or considered too late,” Mr Hunter said. “Executives need to look to the future. IT risk management is working the way it should when it is simply part of the way the company does business.”



PRACTICE
more articles ( 172 )  more articles ( 172 ) 
Business
8 serious symptoms of burn-out go
Business
5 golden rules when handling complaints go
Business
4 traps in decision-making go
MARKET-TRENDS
more articles ( 130 )  more articles ( 130 ) 
Human Ressource
Recognizing top performers with personnel assessment go
IBM reveals:
Five innovations that will change our lives in the next five years go
Results of major AMD European Survey:
Europe is turning into a Continent of Content-Craving 'Connect-aholics' go
CAREER TIPS
more articles ( 12 )  more articles ( 12 ) 
Personality
Checklist: What kind of winning personality are you? go
Economic crisis
Employees Losing Sleep and Health go
Culpepper
2010 Salary Increase Budgets Projected to Rise Worldwide go
PRODUCT INNOVATIONS
hide articles  hide articles 
Stock Market - Trading Tips
Great ideas and tips for stock market beginners go
Made in IBM Labs: technology to aid human memory
New software helps people struggling with information overload go
Gamercize - electronic motivator
Fitness machine launched for office workers go
Text Internet Marketing
Free express web test go
BTS - customizes business simulations
Business strategies in a risk free environment go
EU - CONTEXT project
A vest to measure stress go
Biyn Development - websites
Not just another pretty face go
Online business
New product helps online merchants boost sales go
Greyfirst - free public availability
World's first pre-production software go
Grützmacher - Document processing machines
New mail processing machine go
Comodo - secure
A new service that helps keep user information safe during wireless sessions go
ConnectCode - multiple barcodes
Barcode fonts with Add-In for Excel simplifies creation of multiple barcodes go
BeamYourScreen
Putting the eye into iPhone go
TraceWorks - web application
Manage marketing campaigns on an iPhone go
Inventory Management System
Inventory management system maintain the balance of supply and demand go
halfpricesoft - payroll software
Do-It-Yourself payroll software for small business go
Siemens - Internet ID card
New internet ID card prevents online fraud go
LTS - industry-specific tools
The next generation in lead tracking solutions go
Project "TRADE"
Clock synchronization between smart card and server protects against fraudulent users go
E-Cig - electronic cigarette
Gamucci launch the electronic cigarette go
Elegant MicroWeb - Business Intelligence Suite
One complete product bringing business intelligence for everyone, anywhere, anytime go
Zelfi - mobile software
Free GPS navigation for the cell phone go
Dr. Detlef Meyer-Eltz - analysis of texts
Debugging look-ahead productions go


 News - 24.05.2013
 back    top