![]() |
“Tsunami” is the Japanese term for a series of violent and recurrent waves in the ocean caused by the displacement of a large volume of water. Earthquakes, volcanic eruptions, landslides or other underwater explosions or man-made events are usually the cause. Unlike normal ocean waves that are generated by wind, or tides that are generated by the gravitational pull of the Moon and Sun, a tsunami is much less predictable and often more sudden and impactful. Do you ever feel like your organization is navigating an unrelenting tsunami of issues generated by multiple groups, such as audit, risk, and compliance, or external auditors and regulators? These fierce waves are usually caused by risk management activities, threats, cyber events, non-compliance with regulations or other forces. Like tsunamis we don’t see coming, today’s business environment is a challenge for issues management, regardless of your industry, geographic location, or business model. With constant regulatory change, shifts in business strategies and rapid technology transformations, it is easy to become overwhelmed by the magnitude, velocity, and complexity of issues that must be addressed. Like dealing with the aftermath of a tsunami, remediation plans many organizations put in place to “clean up” are reactive, short term and may not solve the real problem. Let’s look at how most organizations deal with their issues and remediation plans.
To properly address issue management, organizations need a strategic and comprehensive approach, including the following:
There are other requirements, but these are a few critical areas to set the stage, enable quick implementation of the process and drive buy-in across the organization. Preparing for tsunamis won’t eliminate all the risk or impacts, but it can significantly reduce the effects and make clean up afterwards that much more manageable. Similarly, implementing a well-thought-out issues management process reduces much of the risk of the findings that are sure to come, as well as make the remediation process that much more complete, streamlined and consistent. For more discussion, email me at Patrick.potter@rsa.com The post Facing a Tsunami of Issues? appeared first on Speaking of Security - The RSA Blog. |
