Editor’s Note: No one should be surprised to find that a NIST-developed Framework has a metric-centric perspective. Plan accordingly.
From: SmartSecurityGridBlog
Posted by Andy Bochman
Thanks to Dark Reading for covering the RSA 2013 metrics panel and for the article: “Governance Without Metrics Is Just Dogma.”
To whom do we owe this powerful and provocative headline? Not the editors at Dark Reading, though they were smart enough to grab it and put it at the top. It was Alex Hutton, an Operations Risk and Governance director at Zions National Bank.
In case you’re not used to seeing the word dogma in this context, let’s refresh ourselves with a definition (thanks Wikipedia):
Dogma is an official system of belief or doctrine held by a religion, or a particular group or organization. It serves as part of the primary basis of an ideology or belief system.
While there are appropriate places and good uses for dogma, the C-Suite and Board of Directors conference table is not one of them. (At this point I can imagine some long-term readers saying, “tell us how you really feel”).
You know what you call governance guided by metrics? Risk management.
Leave a Reply