Avoiding the risk of poor community decisions
Every week when we read our local paper, there is a story about some contentious community problem. It seems community leaders are often trying to explain themselves after the fact; when “solutions” are already underway. Projects are stopped, lawsuits filed, and the cost of the solution suddenly skyrockets. How can a community reduce its exposure to these very real, very expensive risks?
Author Archives: greg
#7 – DOES THE CIO NEED A CISO? – JOHN MILLICAN
That may seem a strange question from an ex-CISO like me so let me be clear. The enterprise almost undoubtedly needs a CISO. But, it is my proposal that the CISO may be more effective reporting into another functional area. It depends on what type of CIO you are, and what your organization needs from its information security program. Continue reading
#6 – I QUIT! WORKING FOR YOU ISN’T WORKING ISN’T WORKING FOR ME – ELIZABETH LIONS
We are often asked to review books. Elizabeth Lions I Quit! Working For You Isn’t Working For Me is a must-read and must-buy book.#6 – CHANGES COMING SOON TO ISO 9001 AND COSO – SANDFORD LIEBESMAN – QUALITY@RISK
I’m a committee member for two very different standards—ISO 9001 and the COSO internal control guidance document used to comply with the requirements of the Sarbanes-Oxley Act (SOX).1 While these documents cover different activities in an organization, they share a need to update the current versions.
COSO is a management system that was originally developed in the 1980s in response to the savings and loan scandal. It is used for internal control over operations and compliance to external financial reporting requirements. COSO consists of five elements used to manage systems of internal control: Continue reading
#6 – SOFTWARE DEFECT ORIGINS AND REMOVAL METHODS – (C) CAPERS JONES – TECHNOLOGY@RISK
The cost of finding and fixing bugs or defects is the largest single expense element in the history of software. Bug repairs start with requirements and continue through development. After release bug repairs and related customer support costs continue until the last user signs off. Over a 25 year life expectancy of a large software system in the 10,000 function point size range almost 50 cents out of every dollar will go to finding and fixing bugs. Continue reading