Home / Insights

Insights

Find the piece that matches the pressure you are under.

Each of these ends in something you can actually do next, rather than in a newsletter signup. Below them is a glossary of the terms we can say something useful about. If none of it describes your situation, the four sentences on the home page are a faster way in.

Why there are so few

Everything here has to name a pressure someone is actually under and end in a step they can take. Writing that takes longer than writing opinions, so the list grows slowly — which we prefer to a blog nobody finishes.

Where a piece was first published elsewhere, it says so. An article that survived an editorial review is worth more with that provenance attached than without it.

Glossary

The terms, and what we actually do about them.

Each entry gives the plain definition, then says where MyRISK fits — and where it doesn't. Several say we are not the answer, which is more useful than a definition that pretends otherwise.

Board risk reporting

Reporting risk to a board or executive committee in a form it can act on.

CIS Controls

A prioritised set of defensive actions published by the Center for Internet Security.

COBIT

ISACA's framework for the governance and management of enterprise IT.

Continuous control monitoring

Testing control operation on an ongoing basis rather than at a point in time.

Crosswalking

Mapping the controls of one framework onto another so a single control answers both.

Cyber resilience

The ability to keep operating through a cyber incident and recover afterwards.

Enterprise risk management (ERM)

Managing risk across a whole organisation rather than function by function.

Governance, risk and compliance (GRC)

The combined discipline of directing an organisation, managing what could go wrong, and evidencing obligations.

Information security risk management

Applying risk management to the confidentiality, integrity and availability of information.

Integrated risk management (IRM)

Connecting risk, control, assurance and performance information so they inform one another.

Internal audit risk management

The independent function that tests whether controls and governance work as described.

ISMS

An information security management system — the governing structure ISO 27001 requires.

ISO 27001

The international standard for an information security management system.

IT risk management

Identifying and treating risk arising from technology systems, data and their operation.

NIST Cybersecurity Framework

A voluntary US framework organising cyber security into functions: govern, identify, protect, detect, respond, recover.

Operational risk management

Managing the risk of loss from failed internal processes, people, systems or external events.

Policy management

Creating, approving, publishing, attesting and reviewing organisational policy.

Responsible AI

Governing AI systems so their use is accountable, explainable and reviewable.

Risk assessment

The process of identifying what could go wrong, how likely it is, and what it would cost.

Risk categories

The groupings an organisation uses to sort risk — strategic, operational, financial, compliance, technology and others.

Risk management framework

The structure that says how an organisation identifies, assesses, treats and reports risk.

Risk register

A list of identified risks with their owners, assessments and treatments.

SOC 2

A US attestation report on a service organisation's controls, issued by an auditor.

Third-party risk management (TPRM)

Assessing and governing the risk introduced by suppliers, vendors and partners.

Not sure which of these you are?

The home page asks it in four sentences, in your words rather than ours.