Managing Risk in Information Technology

As information technology increasingly falls within thevarious organizations. ISO/IEC 20000, the IT service
scope of corporate governance, so managementmanagement standard, provides a best-practice
must increasingly focus on the management of riskspecification that sits on top of the ITIL.
to the achievement of its business objectives.Regulatory and Compliance Risk
There are two fundamental components of effectiveAll organizations are subject to a range of
management of risk in information and informationinformation-related national and international legislation
technology: the first relates to an organization'sand regulatory requirements. These range from broad
strategic deployment of information technology incorporate governance guidelines to the detailed
order to achieve its corporate goals, the secondrequirements of specific regulations. UK organizations
relates to risks to those assets themselves.are subject to some, or all, of:
IT systems usually represent significant investmentsCombined Code and Turnbull Guidance (UK)
of financial and executive resources. The way inBasel2
which they are planned, managed and measuredEU data protection, privacy regimes
should therefore be a key managementSectoral regulation: FSA (1) , MiFID (2) , AML (3)
accountability, as should the way in which risksHuman Rights Act, Regulatation of Investigatory
associated with information assets themselves arePowers Act
managed.Computer misuse regulation
Clearly, well managed information technology is aThose organizations with US operations may also be
business enabler. Every deployment of informationsubject to US regulations such as Sarbanes Oxley
technology brings with it immediate risks to theand SEC regulations, as well as sectoral regulation
organization and, therefore, every director orsuch as GLBA (4), HIPAA (5) and USA PATRIOT
executive who deploys, or manager who makes anyAct. Most organizations are possibly also subject to
use of, information technology needs to understandUS state laws that appear to have wider applicability,
these risks and the steps that should be taken toincluding SB 1386 (California Information Practice Act)
counter them.and OPPA (6).
ITIL, the Information Technology InfrastructureCompliance depends as much on information security
Library, has long provided an extensive collection ofas on IT processes and services. Many of these
best practice IT management processes andregulations have emerged only recently and most
guidance. In spite of an extensive range ofhave not yet been adequately tested in the courts.
practitioner-orientated certified qualifications, it is notThere has been no co-ordinated national or
possible for any organization to prove - to itsinternational effort to ensure that many of these
management, let alone an external third party - thatregulations - particularly those around personal privacy
it has taken the risk-reduction step of implementingand data protection - are effectively co-ordinated.
best practice.As a result, there are overlaps and conflicts between
More than that, ITIL is particularly weak wheremany of these regulations and, while this is of little
information security management is concerned - theimportance to organizations trading exclusively within
ITIL book on information security really does noone jurisdiction, the reality is that many enterprises
more than refer to a now very out-of-date versiontoday are trading on an international basis, particularly
of ISO 17799, the information security code ofif they have a website or are connected to the
practice.Internet.
The emergence of the international IT ServiceManagement Systems
Management (ISO 27001) and Information SecurityA management system is a formal, organized
Management (ISO20000) standards changes all this.approach used by an organization to manage one or
They make it possible for organizations that havemore components of their business, including quality,
successfully implemented an ITIL environment to bethe environment and occupational health and safety,
externally certificated as having information securityinformation security and IT service management.
and IT service management processes that meet anMost organizations - particularly younger, less mature
international standard; organizations that demonstrateones, have some form of management system in
- to customers and potential customers - the qualityplace, even if they're not aware of it. More
and security of their IT services and informationdeveloped organizations use formal management
security processes achieve significant competitivesystems which they have certified by a third party
advantages.for conformance to a management system standard.
Information Security RiskOrganizations that use formal management systems
The value of an independent information securitytoday include corporations, medium- and small-sized
standard may be more immediately obvious to thebusinesses, government agencies, and
ITIL practitioner than an IT service management one.non-governmental organizations (NGOs).
The proliferation of increasingly complex,Standards and Certifications
sophisticated and global threats to informationFormal standards provide a specification against which
security, in combination with the complianceaspects of an organization's management sytsem can
requirements of a flood of computer- andbe independently audited by an accredited
privacy-related regulation around the world, is drivingcertification body and, if the management system is
organizations to take a more strategic view offound to conform to the specification, the
information security.organization can be issued with a formal certificate
It has become clear that hardware-, software- orconfirming this. Organizations that are certificated to
vendor-driven solutions to individual informationISO 9000 will already be familiar with the certification
security challenges are, on their own, dangerouslyprocess.
inadequate. ISO/IEC 27001 (what was BS7799) helpsIntegrated Management Systems
organizations make the step to sytematicallyOrganizations can choose to certify their
managing and controlling risk to their informationmanagement systems to more than one standard.
assets.This enables them to integrate the processes that
IT Process Riskare common - management review, corrective and
IT must be managed systematically to support thepreventative action, control of documents and
organization in achieving its business objectives, or itrecords, and internal quality audits - to each of the
will disrupt business processes and underminestandards in which they are interested.
business activity. IT management, of course, has itsThere is already an alignment of clauses in ISO 9000,
own processes - and many of these processes areISO 14001 (the environmental management system
common across organizations of all sizes and in manystandard) and OHSAS 18001 (the health and safety
sectors.management standard) that supports this integration,
Processes deployed to manage the IT organizationand which enables organizations to benefit from
itself need both to be effective and to ensure thatlower cost initial audits, fewer surveillance visits and
the IT organization delivers against business needs. ITwhich, most importantly, allows organizations to 'join
service management is a concept that embraces theup' their management systems.
notion that the IT organization (known, in ISO/IECThe emergence of these international standards now
20000 as in ITIL, as the "service provider") exists toenables organizations to develop an integrated IT
deliver services to business users, in line with businessmanagement system that is capable of multiple
needs, and to ensure the most cost-effective use ofcertification and of external, third party audit, while
IT assets within that overall context.drawing simultaneously on the deeper best-practice
ITIL, the IT Infrastructure Library, emerged as acontained in ITIL. This is a huge step forward for the
collection of best practices that could be used inITIL world.