Showing posts with label theory. Show all posts
Showing posts with label theory. Show all posts

Tuesday, March 30, 2010

Governance Part 4: Standards

We’ve covered how management uses policies to govern an undertaking, whether that’s a business, a household, or one’s career. Today we’ll continue the Governance series with a look at standards and how they bridge the gap between executive ideals and technical practicality.

The relationship between a policy and a standard is similar to the relationship between a vision and a mission:

Monday, March 15, 2010

Managing Risk Through Acceptance and Assignment

Last week, we looked at risk mitigation. If you do something to reduce your vulnerability to a threat, or the impact of that threat, the risk goes down. Your personal firewall, your anti-virus system, the lock on your front door, and the umbrella you carry when it looks cloudy out are all examples of risk mitigation. It’s a very popular way to manage risk, and literal billions of dollars of the economy are people the world over mitigating trillions of dollars of risk. Mitigation very nearly always costs money, and frequently it’s the most cost effective way to manage one’s risk, but there are others. Today we’ll take a short look at two of them: Acceptance and Assignment.

Tuesday, March 9, 2010

Risk Management: Risk Mitigation

Last week, I started talking about risk management by talking about how it relates to something as mundane as forgetting your car keys. I’m going to stick with that analogy as we discuss how to use risk assessment to understand whether you’re happy with the risk you have or if it’s worth spending some money to mitigate that risk.

Friday, March 5, 2010

Governance Part 3: Policies

In Part 2, we discussed the Missions, Visions, and Charters, which define a task, lay out an overall strategy for accomplishing that task, and authorize someone to do it. Today, we’ll discuss how policies tell everyone to execute the charter to accomplish the mission that realizes the vision. (If I can make this into a spoof of The Court of King Caractacus, why not?).

Humor aside, a policy is a high level statement from senior management to the enterprise describing how it expects everyone to conduct business.

Monday, March 1, 2010

Risk Management: YOU Are a risk manager!

Risk management. Assessment, Vulnerabilities, threats, and impact. Mitigation, assignment, acceptance. If you don’t do security for a living, or do it as a purely technical activity, these can sound like terms from some arcane art practiced by Wizards, Sorcerers, Actuaries, and Mutual Fund managers. Today we start taking the mystique out of it and showing that it’s something nearly everyone does every day.