Similar Searches

  • Elements of Optimized Security: Automated Compliance (September 7, 2010)

    As a CIO or CISO, you’re constantly reminded that your job is to reduce costs, improve security and achieve compliance. And, if you’re like the many IT leaders I’ve worked with, I wouldn’t be surprised if you said you felt

  • IT Governance, Risk, and Compliance (April 8, 2010)

    IT Governance, Risk, and Compliance (GRC): A method of analysis based on the Symantec Response Assessment Module (RAM) 1.1    Introduction 1.2    GRC Analysis: a new method based on the Symantec Response Assessment Module           1.2.1    PHASE 1: Design           1.2.2    PHASE

  • IT Governance, Risk, and Compliance – Part II (May 21, 2010)

    IT Governance, Risk, and Compliance: A method of analysis based on the Symantec Response Assessment Module (RAM) Part I of this blog series introduced the concepts of IT governance, risk, and compliance (GRC). To quote: “In recent times, companies, organizations,

  • Taking compliance to the endpoint and beyond (August 11, 2009)

    In June McAfee acquired Solidcore, a leading provider of dynamic whitelisting technology. Today, under the McAfee name, we offer the industry’s first end-to-end compliance solution that includes dynamic whitelisting and application trust technology. In my opinion, this technology is

  • The McAfee Risk Management Solution (July 19, 2010)

    In a recent Technical Brief by Enterprise Strategy Group Principal Analyst Jon Oltsik titled, “Large Organizations are Way Behind on IT Risk Management,” he reflects in the abstract, “Without rapid IT risk management progress, many organizations

Related News

  • Elements of Optimized Security: Automated Compliance (September 7, 2010)

    As a CIO or CISO, you’re constantly reminded that your job is to reduce costs, improve security and achieve compliance. And, if you’re like the many IT leaders I’ve worked with, I wouldn’t be surprised if you said you felt

  • IT Governance, Risk, and Compliance (April 8, 2010)

    IT Governance, Risk, and Compliance (GRC): A method of analysis based on the Symantec Response Assessment Module (RAM) 1.1    Introduction 1.2    GRC Analysis: a new method based on the Symantec Response Assessment Module           1.2.1    PHASE 1: Design           1.2.2    PHASE

  • IT Governance, Risk, and Compliance – Part II (May 21, 2010)

    IT Governance, Risk, and Compliance: A method of analysis based on the Symantec Response Assessment Module (RAM) Part I of this blog series introduced the concepts of IT governance, risk, and compliance (GRC). To quote: “In recent times, companies, organizations,

  • Taking compliance to the endpoint and beyond (August 11, 2009)

    In June McAfee acquired Solidcore, a leading provider of dynamic whitelisting technology. Today, under the McAfee name, we offer the industry’s first end-to-end compliance solution that includes dynamic whitelisting and application trust technology. In my opinion, this technology is

  • The McAfee Risk Management Solution (July 19, 2010)

    In a recent Technical Brief by Enterprise Strategy Group Principal Analyst Jon Oltsik titled, “Large Organizations are Way Behind on IT Risk Management,” he reflects in the abstract, “Without rapid IT risk management progress, many organizations

Gartner Risk and Compliance Summit

This year’s theme at the Gartner Risk and Compliance Summit centered on directions and tools to help organizations maximize their Governance, Risk and Compliance programs. No doubt, a reflection of the current economic climate.


Especially interesting was that few vendors really had anything innovative or different to offer compared to last year. Some were niche vendors who solve one piece of the puzzle but are trying to expand their offerings while others were broader GRC vendors that had matured their offerings.


What was clearly apparent is that customers are more then ever bent on consolidating vendors. The idea that you could have one platform to manage both security and compliance and with separation of duties built in, has gained momentum. And, controls automation, while a well-worn topic is also something that customers are becoming much more serious about as part of reducing the cost of audits.


McAfee co-presented a session with Tyco International on leveraging a risk-based approach to sustain compliance efforts, which resonated very well with attendees. Taking a risk-based approach could have helped mitigate some of the most publicized recent data breaches. Through regular automated audits and vulnerability scans and applying countermeasures to reduce residual risk, organizations can focus on assets most at risk – we call this the 80-20 rule.


Tyco International talked about

Continue reading...


Copyright © 2010 The Security Blog. All rights reserved.