{"id":572,"date":"2013-09-15T17:05:44","date_gmt":"2013-09-15T22:05:44","guid":{"rendered":"http:\/\/www.webadminblog.com\/?p=572"},"modified":"2013-09-15T17:05:44","modified_gmt":"2013-09-15T22:05:44","slug":"enterprise-risk-management-for-the-masses","status":"publish","type":"post","link":"https:\/\/www.webadminblog.com\/index.php\/2013\/09\/15\/enterprise-risk-management-for-the-masses\/","title":{"rendered":"Enterprise Risk Management for the Masses"},"content":{"rendered":"<p>A couple of years ago I decided, along with support from my management, that Enterprise Risk Management would become a focal point for my Information Security Program.\u00a0 I was convinced that framing vulnerabilities in the form of risks was essential to giving management visibility into issues they currently didn&#8217;t know existed and to give our staff the comfort of knowing that the issues that caused them to lose sleep at night were now being considered for mitigation by management.\u00a0 I couldn&#8217;t have been more right.<\/p>\n<p>I began by collecting the risks submitted by each team in Excel spreadsheets and Word documents.\u00a0 They had all of the pertinent information like a subject, owner, risk assessment, etc, but very quickly I became a victim of my own success.\u00a0 Before I knew it, I had more risks than I could efficiently track in this format.\u00a0 First off, it was extremely cumbersome to try to manually maintain the risk index in Excel.\u00a0 While Excel is good at calculating formulas, it sucks at maintaining links to external documents.\u00a0 It can be done, but it requires quite a bit of manual effort to do so.\u00a0 Second, maintaining your risk details in Word documents is something they should reserve only for your worst enemies.\u00a0 They are difficult to update, difficult to track updates with, difficult to search and, well, just plain difficult.\u00a0 I thought to myself that there has to be a better way, yet, this is what the unfortunate majority out there are currently stuck with today.<\/p>\n<p>After some research, it turns out that many years back, my company had another security professional who was interested in Enterprise Risk Management.\u00a0 Apparently, they had come to similar conclusions as I did with the Word documents and Excel spreadsheets, but they were able to get some internal development time to create a Lotus Notes based risk management database.\u00a0 It was everything that I needed, or so I thought, so I started to manually enter all of my new risks into this old risk management database.\u00a0 At first, things seemed to be working well.\u00a0 I had some different views into my data that would allow me to see way more information than I could before.\u00a0 I also had the ability for management of our various teams to be able to see their risks without involving me.\u00a0 It was much better, but soon I began to realize the limitations of this approach.\u00a0 The database itself was rigid.\u00a0 Changes required me to go through another internal team for resources and it often took a long time to make them.\u00a0 Also, any updates that were made didn&#8217;t modify the current risks, only the ones submitted after that point.\u00a0 Once, I found myself opening and re-saving hundreds of risks just because I decided to change my risk calculation formula slightly.\u00a0 I began looking again for another way.<\/p>\n<p>Soon, my new round of research brought me to a special set of tools called Governance, Risk, and Compliance or GRC for short.\u00a0 There are a number of such tools out there by well-resepcted companies such as EMC Archer and CA.\u00a0 They looked completely awesome and seemed to solve all of my problems with many more features to spare so I started to get some SWAG quotes from a few of the vendors.\u00a0 Low and behold, these tools hold a pricetag of $100k to half a million dollars and beyond.\u00a0 A request for budget for one of these tools was dismissed immediately with management literally laughing at my suggestion.\u00a0 OK, so maybe it was on me, right?\u00a0 Maybe I didn&#8217;t do a good enough job of selling the tool?\u00a0 Maybe I didn&#8217;t engage the right stakeholders to back my request?\u00a0 I guess you could call me a glutton for punishment, but I decided to keep trying.\u00a0 This time I gathered people I thought would be interested in risk from all different areas of our business for a demo of one of the tools.\u00a0 Trade Compliance, Health and Safety, Facilities, Legal, and many more.\u00a0 They watched the presentation, asked some fantastic questions, and ultimately left that meeting saying that they thought that a GRC solution was a fantastic idea.\u00a0 That was until I mentioned the price tag.\u00a0 If even with a budget split between half a dozen different teams, it wasn&#8217;t going to happen, I knew that it simply wasn&#8217;t going to happen.<\/p>\n<p>As I began to think about the situation that I was in, I realized that I wasn&#8217;t alone in all this.\u00a0 I talked with friends at various state agencies, friends at risk consultancies, and friends at companies large and small.\u00a0 They had gone through the same trials and tribulations that I had and fared no better for the most part.\u00a0 Having spent the better part of the last decade coding random applications and websites in PHP and MySQL, I decided that there may be something that I could do about it.\u00a0 I would go home from work and start coding until the wee hours of the morning.\u00a0 I would wake up early on my weekends and start coding again until the family awoke.\u00a0 After several weeks of this, I had a working prototype for a new risk management system based on some simplifications of the NIST 800-30 risk management framework and running on my LAMP (Linux Apache MySQL PHP) stack.\u00a0 <a href=\"http:\/\/www.simplerisk.org\" target=\"_blank\">SimpleRisk<\/a> was born.<\/p>\n<p>At the time of this writing, I have released 7 official versions of SimpleRisk since March of this year.\u00a0 It has come a long way since then, but still holds true to it&#8217;s roots.\u00a0 SimpleRisk is free and open source.\u00a0 The methodology was designed to be as simple as possible, hence the name.\u00a0 A five step process walks you through the basics of risk management:<\/p>\n<ol>\n<li>Submit your risks<\/li>\n<li>Plan your mitigations<\/li>\n<li>Perform management reviews<\/li>\n<li>Prioritize for project planning<\/li>\n<li>Review regularly<\/li>\n<\/ol>\n<p>It has every basic feature required of an enterprise risk management system and I&#8217;m adding new ones all the time.\u00a0 It has five different ways to weight classic risk calculations (ie. likelihood and impact) and can perform CVSS scoring as well.\u00a0 It has it&#8217;s own built-in authentication system, but I&#8217;ve built an extra module to do LDAP authentication that I&#8217;m giving away to anyone who donates $500 or more to the cause.\u00a0 It also has a half-dozen different ways to report on the risks and many more reports should be complete soon.\u00a0 You can check out the demo (minus the Administrator interface) using the username &#8220;user&#8221; and password &#8220;user&#8221; at <a href=\"http:\/\/demo.simplerisk.org\" target=\"_blank\">http:\/\/demo.simplerisk.org<\/a>.\u00a0 Or, if you&#8217;re ready to dive right in, you can obtain the download package for free at <a href=\"http:\/\/www.simplerisk.org\" target=\"_blank\">http:\/\/www.simplerisk.org<\/a>.<\/p>\n<p>In order to make your foray into SimpleRisk as simple as possible, I&#8217;ve created a <a href=\"http:\/\/simplerisk.googlecode.com\/files\/SimpleRisk%20LAMP%20Installation%20Guide.pdf\" target=\"_blank\">SimpleRisk LAMP Installation Guide<\/a> that you can use to have the tool up and running in about 30-60 minutes.\u00a0 And if all else fails and that proves too difficult or time consuming, then you should make your way to <a href=\"http:\/\/www.hostedrisk.com\" target=\"_blank\">http:\/\/www.hostedrisk.com<\/a> where for a fraction of what it would cost to buy a GRC solution, you will have your own dedicated SimpleRisk instance, running on hardware dedicated to you, built with security in mind, including extra modules not part of the standard distribution, and you&#8217;ll never have to worry about installing or upgrading risk management software ever again.\u00a0 Hopefully you won&#8217;t ever need this, but the option is always there in case you do.<\/p>\n<p>My frustrations with a lack of efficient and cost-effective risk management tools led me to create one of my own.\u00a0 My hope is that by making SimpleRisk free and open source, it will benefit the rest of the security community as much as it has already benefited me.\u00a0 If you have any questions or requests for features that you would like to see included in the tool, I&#8217;m always here to help.\u00a0 SimpleRisk is simple, enterprise risk management, for the masses.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A couple of years ago I decided, along with support from my management, that Enterprise Risk Management would become a focal point for my Information Security Program.\u00a0 I was convinced that framing vulnerabilities in the form of risks was essential to giving management visibility into issues they currently didn&#8217;t know existed and to give our [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[547,546,96],"tags":[206,237,552,548,550,18,619,555,554,553,161,556,133,534,549,629,496,551,156,102],"class_list":["post-572","post","type-post","status-publish","format-standard","hentry","category-grc","category-risk-management","category-software-and-tools","tag-apache","tag-compliance","tag-free","tag-governance","tag-grc-2","tag-linux","tag-management","tag-mitigation","tag-mysql","tag-open","tag-php","tag-planning","tag-project","tag-review","tag-risk","tag-saas","tag-simple","tag-simplerisk","tag-source","tag-web"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"A couple of years ago I decided, along with support from my management, that Enterprise Risk Management would become a focal point for my Information Security Program. I was convinced that framing vulnerabilities in the form of risks was essential to giving management visibility into issues they currently didn&#039;t know existed and to give our\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Josh\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.webadminblog.com\/index.php\/2013\/09\/15\/enterprise-risk-management-for-the-masses\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Web Admin Blog | Real Web Admins.  Real World Experience.\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Enterprise Risk Management for the Masses | Web Admin Blog\" \/>\n\t\t<meta property=\"og:description\" content=\"A couple of years ago I decided, along with support from my management, that Enterprise Risk Management would become a focal point for my Information Security Program. I was convinced that framing vulnerabilities in the form of risks was essential to giving management visibility into issues they currently didn&#039;t know existed and to give our\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.webadminblog.com\/index.php\/2013\/09\/15\/enterprise-risk-management-for-the-masses\/\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2013-09-15T22:05:44+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2013-09-15T22:05:44+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Enterprise Risk Management for the Masses | Web Admin Blog\" \/>\n\t\t<meta name=\"twitter:description\" content=\"A couple of years ago I decided, along with support from my management, that Enterprise Risk Management would become a focal point for my Information Security Program. I was convinced that framing vulnerabilities in the form of risks was essential to giving management visibility into issues they currently didn&#039;t know existed and to give our\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/2013\\\/09\\\/15\\\/enterprise-risk-management-for-the-masses\\\/#article\",\"name\":\"Enterprise Risk Management for the Masses | Web Admin Blog\",\"headline\":\"Enterprise Risk Management for the Masses\",\"author\":{\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/author\\\/jsokol\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/#organization\"},\"datePublished\":\"2013-09-15T17:05:44-05:00\",\"dateModified\":\"2013-09-15T17:05:44-05:00\",\"inLanguage\":\"en-US\",\"commentCount\":2,\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/2013\\\/09\\\/15\\\/enterprise-risk-management-for-the-masses\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/2013\\\/09\\\/15\\\/enterprise-risk-management-for-the-masses\\\/#webpage\"},\"articleSection\":\"GRC, Risk Management, Software and Tools, apache, compliance, free, governance, grc, linux, Management, mitigation, mysql, open, php, planning, project, review, risk, SaaS, simple, simplerisk, source, web\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/2013\\\/09\\\/15\\\/enterprise-risk-management-for-the-masses\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.webadminblog.com#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.webadminblog.com\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/category\\\/security\\\/#listItem\",\"name\":\"Security\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/category\\\/security\\\/#listItem\",\"position\":2,\"name\":\"Security\",\"item\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/category\\\/security\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/category\\\/security\\\/risk-management\\\/#listItem\",\"name\":\"Risk Management\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.webadminblog.com#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/category\\\/security\\\/risk-management\\\/#listItem\",\"position\":3,\"name\":\"Risk Management\",\"item\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/category\\\/security\\\/risk-management\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/2013\\\/09\\\/15\\\/enterprise-risk-management-for-the-masses\\\/#listItem\",\"name\":\"Enterprise Risk Management for the Masses\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/category\\\/security\\\/#listItem\",\"name\":\"Security\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/2013\\\/09\\\/15\\\/enterprise-risk-management-for-the-masses\\\/#listItem\",\"position\":4,\"name\":\"Enterprise Risk Management for the Masses\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/category\\\/security\\\/risk-management\\\/#listItem\",\"name\":\"Risk Management\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/#organization\",\"name\":\"Web Admin Blog\",\"description\":\"Real Web Admins.  Real World Experience.\",\"url\":\"https:\\\/\\\/www.webadminblog.com\\\/\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/author\\\/jsokol\\\/#author\",\"url\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/author\\\/jsokol\\\/\",\"name\":\"Josh\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/2013\\\/09\\\/15\\\/enterprise-risk-management-for-the-masses\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/b9a6f9a4045419aaa65743aba583ce8c1b6d6d7789e949e44c9853914aecf2e9?s=96&d=identicon&r=pg\",\"width\":96,\"height\":96,\"caption\":\"Josh\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/2013\\\/09\\\/15\\\/enterprise-risk-management-for-the-masses\\\/#webpage\",\"url\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/2013\\\/09\\\/15\\\/enterprise-risk-management-for-the-masses\\\/\",\"name\":\"Enterprise Risk Management for the Masses | Web Admin Blog\",\"description\":\"A couple of years ago I decided, along with support from my management, that Enterprise Risk Management would become a focal point for my Information Security Program. I was convinced that framing vulnerabilities in the form of risks was essential to giving management visibility into issues they currently didn't know existed and to give our\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/2013\\\/09\\\/15\\\/enterprise-risk-management-for-the-masses\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/author\\\/jsokol\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/author\\\/jsokol\\\/#author\"},\"datePublished\":\"2013-09-15T17:05:44-05:00\",\"dateModified\":\"2013-09-15T17:05:44-05:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/#website\",\"url\":\"https:\\\/\\\/www.webadminblog.com\\\/\",\"name\":\"Web Admin Blog\",\"description\":\"Real Web Admins.  Real World Experience.\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Enterprise Risk Management for the Masses | Web Admin Blog","description":"A couple of years ago I decided, along with support from my management, that Enterprise Risk Management would become a focal point for my Information Security Program. I was convinced that framing vulnerabilities in the form of risks was essential to giving management visibility into issues they currently didn't know existed and to give our","canonical_url":"https:\/\/www.webadminblog.com\/index.php\/2013\/09\/15\/enterprise-risk-management-for-the-masses\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.webadminblog.com\/index.php\/2013\/09\/15\/enterprise-risk-management-for-the-masses\/#article","name":"Enterprise Risk Management for the Masses | Web Admin Blog","headline":"Enterprise Risk Management for the Masses","author":{"@id":"https:\/\/www.webadminblog.com\/index.php\/author\/jsokol\/#author"},"publisher":{"@id":"https:\/\/www.webadminblog.com\/#organization"},"datePublished":"2013-09-15T17:05:44-05:00","dateModified":"2013-09-15T17:05:44-05:00","inLanguage":"en-US","commentCount":2,"mainEntityOfPage":{"@id":"https:\/\/www.webadminblog.com\/index.php\/2013\/09\/15\/enterprise-risk-management-for-the-masses\/#webpage"},"isPartOf":{"@id":"https:\/\/www.webadminblog.com\/index.php\/2013\/09\/15\/enterprise-risk-management-for-the-masses\/#webpage"},"articleSection":"GRC, Risk Management, Software and Tools, apache, compliance, free, governance, grc, linux, Management, mitigation, mysql, open, php, planning, project, review, risk, SaaS, simple, simplerisk, source, web"},{"@type":"BreadcrumbList","@id":"https:\/\/www.webadminblog.com\/index.php\/2013\/09\/15\/enterprise-risk-management-for-the-masses\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.webadminblog.com#listItem","position":1,"name":"Home","item":"https:\/\/www.webadminblog.com","nextItem":{"@type":"ListItem","@id":"https:\/\/www.webadminblog.com\/index.php\/category\/security\/#listItem","name":"Security"}},{"@type":"ListItem","@id":"https:\/\/www.webadminblog.com\/index.php\/category\/security\/#listItem","position":2,"name":"Security","item":"https:\/\/www.webadminblog.com\/index.php\/category\/security\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.webadminblog.com\/index.php\/category\/security\/risk-management\/#listItem","name":"Risk Management"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.webadminblog.com#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/www.webadminblog.com\/index.php\/category\/security\/risk-management\/#listItem","position":3,"name":"Risk Management","item":"https:\/\/www.webadminblog.com\/index.php\/category\/security\/risk-management\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.webadminblog.com\/index.php\/2013\/09\/15\/enterprise-risk-management-for-the-masses\/#listItem","name":"Enterprise Risk Management for the Masses"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.webadminblog.com\/index.php\/category\/security\/#listItem","name":"Security"}},{"@type":"ListItem","@id":"https:\/\/www.webadminblog.com\/index.php\/2013\/09\/15\/enterprise-risk-management-for-the-masses\/#listItem","position":4,"name":"Enterprise Risk Management for the Masses","previousItem":{"@type":"ListItem","@id":"https:\/\/www.webadminblog.com\/index.php\/category\/security\/risk-management\/#listItem","name":"Risk Management"}}]},{"@type":"Organization","@id":"https:\/\/www.webadminblog.com\/#organization","name":"Web Admin Blog","description":"Real Web Admins.  Real World Experience.","url":"https:\/\/www.webadminblog.com\/"},{"@type":"Person","@id":"https:\/\/www.webadminblog.com\/index.php\/author\/jsokol\/#author","url":"https:\/\/www.webadminblog.com\/index.php\/author\/jsokol\/","name":"Josh","image":{"@type":"ImageObject","@id":"https:\/\/www.webadminblog.com\/index.php\/2013\/09\/15\/enterprise-risk-management-for-the-masses\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/b9a6f9a4045419aaa65743aba583ce8c1b6d6d7789e949e44c9853914aecf2e9?s=96&d=identicon&r=pg","width":96,"height":96,"caption":"Josh"}},{"@type":"WebPage","@id":"https:\/\/www.webadminblog.com\/index.php\/2013\/09\/15\/enterprise-risk-management-for-the-masses\/#webpage","url":"https:\/\/www.webadminblog.com\/index.php\/2013\/09\/15\/enterprise-risk-management-for-the-masses\/","name":"Enterprise Risk Management for the Masses | Web Admin Blog","description":"A couple of years ago I decided, along with support from my management, that Enterprise Risk Management would become a focal point for my Information Security Program. I was convinced that framing vulnerabilities in the form of risks was essential to giving management visibility into issues they currently didn't know existed and to give our","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.webadminblog.com\/#website"},"breadcrumb":{"@id":"https:\/\/www.webadminblog.com\/index.php\/2013\/09\/15\/enterprise-risk-management-for-the-masses\/#breadcrumblist"},"author":{"@id":"https:\/\/www.webadminblog.com\/index.php\/author\/jsokol\/#author"},"creator":{"@id":"https:\/\/www.webadminblog.com\/index.php\/author\/jsokol\/#author"},"datePublished":"2013-09-15T17:05:44-05:00","dateModified":"2013-09-15T17:05:44-05:00"},{"@type":"WebSite","@id":"https:\/\/www.webadminblog.com\/#website","url":"https:\/\/www.webadminblog.com\/","name":"Web Admin Blog","description":"Real Web Admins.  Real World Experience.","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.webadminblog.com\/#organization"}}]},"og:locale":"en_US","og:site_name":"Web Admin Blog | Real Web Admins.  Real World Experience.","og:type":"article","og:title":"Enterprise Risk Management for the Masses | Web Admin Blog","og:description":"A couple of years ago I decided, along with support from my management, that Enterprise Risk Management would become a focal point for my Information Security Program. I was convinced that framing vulnerabilities in the form of risks was essential to giving management visibility into issues they currently didn't know existed and to give our","og:url":"https:\/\/www.webadminblog.com\/index.php\/2013\/09\/15\/enterprise-risk-management-for-the-masses\/","article:published_time":"2013-09-15T22:05:44+00:00","article:modified_time":"2013-09-15T22:05:44+00:00","twitter:card":"summary_large_image","twitter:title":"Enterprise Risk Management for the Masses | Web Admin Blog","twitter:description":"A couple of years ago I decided, along with support from my management, that Enterprise Risk Management would become a focal point for my Information Security Program. I was convinced that framing vulnerabilities in the form of risks was essential to giving management visibility into issues they currently didn't know existed and to give our"},"aioseo_meta_data":{"post_id":"572","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":null,"created":"2025-01-03 18:40:21","updated":"2025-07-17 07:19:31","seo_analyzer_scan_date":null,"focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/www.webadminblog.com\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/www.webadminblog.com\/index.php\/category\/security\/\" title=\"Security\">Security<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/www.webadminblog.com\/index.php\/category\/security\/risk-management\/\" title=\"Risk Management\">Risk Management<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tEnterprise Risk Management for the Masses\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.webadminblog.com"},{"label":"Security","link":"https:\/\/www.webadminblog.com\/index.php\/category\/security\/"},{"label":"Risk Management","link":"https:\/\/www.webadminblog.com\/index.php\/category\/security\/risk-management\/"},{"label":"Enterprise Risk Management for the Masses","link":"https:\/\/www.webadminblog.com\/index.php\/2013\/09\/15\/enterprise-risk-management-for-the-masses\/"}],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/www.webadminblog.com\/index.php\/wp-json\/wp\/v2\/posts\/572","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.webadminblog.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.webadminblog.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.webadminblog.com\/index.php\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.webadminblog.com\/index.php\/wp-json\/wp\/v2\/comments?post=572"}],"version-history":[{"count":4,"href":"https:\/\/www.webadminblog.com\/index.php\/wp-json\/wp\/v2\/posts\/572\/revisions"}],"predecessor-version":[{"id":576,"href":"https:\/\/www.webadminblog.com\/index.php\/wp-json\/wp\/v2\/posts\/572\/revisions\/576"}],"wp:attachment":[{"href":"https:\/\/www.webadminblog.com\/index.php\/wp-json\/wp\/v2\/media?parent=572"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.webadminblog.com\/index.php\/wp-json\/wp\/v2\/categories?post=572"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.webadminblog.com\/index.php\/wp-json\/wp\/v2\/tags?post=572"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}