Why you need a risk-first approach to Compliance | anecdotes

Risk and Compliance? Or maybe, Compliance and risk? The difference is not merely a semantic one, it is philosophical. Some GRC managers believe that risk assessments are just something you have to do in order to comply with certain frameworks. Others believe that your entire Compliance program should be based on a risk-based mindset. 

In this blog, we will cover why – while the first philosophy might be ok when you are starting out – once you reach a certain level of maturity, you MUST adopt a risk-based mindset. Don't worry, we won't leave you hanging, we’ll also dive into some practical steps you can take to start shifting your mindset today.

What came first, the risk or the control?

Let’s start at the very beginning (a very good place to start). What came first? With requirements like “the organization shall define and apply an information security risk assessment process” from ISO/IEC 27001 and “the entity identifies risks to the achievement of its objectives across the entity and analyzes risks as a basis for determining how the risks should be managed” from COSO Principle 7 (CC3.2), it seems pretty straight forward. You perform risk assessments because you need to satisfy control objectives. In other words, risk assessments are the result of control objectives. The end, right? Not quite…

How did we arrive at these control objectives in the first place? How are frameworks, composed of control objectives, born? They are, by design, categorized by potential risk vectors. They provide activities you can perform in order to reduce your organization’s risk exposure within a specific area, from secure development and vendor management to human resources and business continuity. Put differently, controls are mitigating strategies. What are they mitigating? You guessed it, risks. 

So at least we’ve answered the existential question of what came first (risk). But does that mean you should prioritize risks?

Why mature organizations need a risk-based approach 

At the beginning of their Security and Compliance journey, most organizations perform risk assessments as a tick-the-box exercise in order to conform to the requirements of a certification. And while this may mean that risk management is not being performed effectively, it is understandable.

But as organizations mature, their primary Security and Compliance priorities need to shift from being audit centric, towards being risk driven for one simple reason – the more at stake, the less risk the organization is willing to be exposed to. (Just ask management).

This will not have a negative impact on your ability to pass your next audit, as by shifting the focus towards risk management and monitoring the effectiveness of control implementation within the context of the organizational risk appetite, you can provide clear justifications for your approach to the auditor. If, however, you monitor the effectiveness of control implementations solely within the context of a framework, you very well may exceed your organizational risk appetite, as there is no one-size-fits-all framework.

How to adopt a risk-first mindset

So, you’re managing a mature Compliance program and we’ve convinced you it's time for a risk-first mindset. But how can you go about adopting one? Here are three processes you can get started with:

  1. Define your inherent risk profile: A clearly defined inherent risk profile should take into consideration the nature of the organization, the industry the organization operates in, business impact analysis data, legal and regulatory obligations, etc.
  2. Set treatment strategies: Once you have identified the risks for which the inherent risk value exceeds the defined organizational risk appetite, define their treatment strategies.
  3. Implement and monitor controls: Monitor that the controls you have implemented as a part of your treatment strategy are in fact reducing the risk level such that the residual risk level is within the organizational risk appetite.

Next stop: continuous monitoring 

While these steps will help you build a great baseline, it is just a first step. To be able to claim that you have a risk-first mindset, you can’t settle for a point-in-time approach. If you truly want to help your organization stay within its risk appetite, you need an understanding of the real-time status of a given risk; You need to transition into treating risks as living creatures that are constantly changing and evolving. 

What does this look like? Well, remember step three from above? Let’s break it down for a minute. For each of your risks, you have controls that are meant to be mitigating them. But how can you know at any point in time that the controls are actually doing their job? Well, for this you need an approach to your risk management that is based on a live stream of data. You will define risks, determine the right controls and then monitor the data to make sure they are effective. That data in turn will let you know if a control is working, informing your risk level and giving you a real view of your organizational risk. 

A risk-first approach is egg-cellent 

Whether you are ready for data-powered continuous risk monitoring or not, you should start shifting your security and Compliance program towards a risk-first approach. Not only will this make your program more impactful and prepare you for growth, but it will also help you speak in the same risk-centric language that leadership does, making you an even more valuable part of the organization. Good luck!

About the author

The post Why you need a risk-first approach to Compliance | anecdotes appeared first on Security Boulevard.

14 June 2023


>>More