If you have read one of our previous
posts around risk assessments, you probably have a good idea of why a risk assessment matters. You’re probably also familiar with compliance requirements in frameworks such as HITRUST, ISO 27001, or SOC 2. A key component of performing a value-added risk assessment is including the right people in your workshops to gain insight into high-risk areas through each subject matter expert’s lens.
So, Who to Pick for Your Risk Assessment?
Once you have completed some of the preparatory work during your risk assessment, such as reviewing assets in use, data flow diagrams, and critical business processes, you should select key business players that can help manage security, privacy, and compliance risks that your company may face. Depending on how much time is available to perform the risk assessment and the resource availability, I recommend one-on-one working sessions as it reduces opportunities for peer pressure or groupthink and helps individuals speak candidly about the risks they are facing. Functional group interviews are great opportunities to identify common perceptions regarding risks and can be supplemented by targeted individual workshops if time or resource scarcity is a factor.Risk Assessment Workshop Candidates
- Chief Technology Officer (CTO): In a technology organization or a SaaS firm, the buck often stops with the CTO regarding security, and risks that impact the company’s offerings. They are also well-tuned to technology and market risks and will likely serve as a key management stakeholder when it comes to prioritizing risks. (Note: In a services organization, the appropriate person may be the Chief Operating Officer or VP of Services.)
- VP/Director of Development: This is often the best person to identify technical risks and opportunities affecting the products, with insight into the overall resource allocation that can be used to support risk treatment. They also are a great resource for identifying asset-based threats, vulnerabilities, and risks. (Note: In a services organization, this would likely be a practice lead.)
- Engineering/Development Personnel: While the CTO and VP of Engineering can likely address product-level risks, technical personnel, such as developers, can highlight operational risks that impact the product and underlying intangible assets. (Note: In a services organization, this would likely be a delivery team member.)
- Site Reliability Engineering (SRE): If you have an SRE team, it is worth taking the time to talk through your risk management approach with them, and to document the technical risks they believe the organization faces.
- Information Technology (IT): IT is often one of the largest control owners within an organization, owning many of the assets in use in the company, and frequently access control. Not only does it make sense to speak with the Director of IT but with the broader IT function.
- CISO/VP of Security: The security function may be the team conducting the risk assessment, but even then, the CISO/VP of Security should be consulted on the risks and challenges the business is facing. It is especially important to consult this individual on risks from evolving threats, and of not accomplishing security program objectives.
- General Counsel: If your legal function is in-house, they will have a good understanding of the risks the company faces, including market, contractual, or legal risks. Even if your legal function is outsourced, it may be worth paying their hourly rate to have a conversation about risk.
- Human Resources (HR): HR often has the best understanding of risks associated with one of the organization’s most important assets: personnel and knowledge. Having at least one workshop with HR is key to understanding security and enterprise risks associated with human resources.
- Chief Finance Officer (CFO): CFOs often are already experienced risk managers, especially financial risks, and as a result, they often have a great understanding of the risks and challenges the organization faces. They can also be champions for the prioritization of resource allocation for security or compliance initiatives, so obtaining their buy-in on risk management early is a significant benefit to the process.
Phillip Lee
Like our content? Subscribe and stay informed.
Related posts
Tags
- Access Control (3)
- Amazon (1)
- Artificial Intelligence (3)
- Assessment (1)
- Attack Surface (2)
- Attack Surface Management (3)
- Attestation (1)
- Audit (1)
- Awareness Week (3)
- AWS (2)
- Backup And Recovery (1)
- BCAW (4)
- BCMS (1)
- Blackbasta (1)
- Business (16)
- Business Continuity (6)
- Business Continuity Planning (2)
- Caas (1)
- Certification (1)
- Christian Hyatt (19)
- CI (1)
- CISO (8)
- CISO Discussions (24)
- Cloud (1)
- CMMC (1)
- Competitive (1)
- Compliance (17)
- Compliance As A Service (5)
- COVID (1)
- Cyber Risk (6)
- Cyber Risk Management (59)
- Cyber Security Law (2)
- Cybersecurity (26)
- Cybersecurity Controls (4)
- Disaster Recovery (5)
- Engineers (1)
- Ethical Hacking (1)
- EU AI Act (3)
- Exercises (1)
- GDPR (4)
- GRC Tool (6)
- Grit (1)
- Hacking (3)
- Hashcat (1)
- HITRUST (16)
- IaaS (1)
- Information Security (11)
- Internal Audit (2)
- ISO (3)
- ISO 22301 (1)
- ISO 27001 (18)
- ISO 27001 Compliance (19)
- ISO 27018 (1)
- ISO 27701 (2)
- ISO 42001 (6)
- ISO 42005 (1)
- IT Audit (9)
- IT Audit And Compliance (33)
- Kahoot (1)
- Leadership (6)
- Management (1)
- Network Security (4)
- News (5)
- News And Events (20)
- NIST 800 Series (2)
- NIST 800-171 (1)
- OSINT (1)
- Outsourced Pci (1)
- P2pe (1)
- Passwords (3)
- PCI DSS (13)
- Penetration Test (7)
- Penetration Testing (31)
- Pentest Report (1)
- Phishing (1)
- PIA (1)
- Press Release (3)
- Privacy (8)
- Privacy Compliance (7)
- Privacy Impact Assessment (1)
- Privacy Shield (1)
- Ransomeware (1)
- Regulatory Compliance (12)
- Report (2)
- Risk Assessment (5)
- Risk Management (19)
- SDLC (2)
- Security (22)
- Security Advisory (1)
- SOC 2 (18)
- SOC Reporting (23)
- Soc2 (1)
- Strategy (1)
- System Backdoor (1)
- Tabletop (1)
- Training (5)
- VCISO (7)
- Vendor Management (2)
- Vulnerability Management (2)
- Vulnerability Scan (1)
- Wannacry (1)
- Webinars (9)