Newsletters Welcome, Guest Log In | Register

Governance and Risk

From regulatory compliance to corporate governance structure, everyone is involved

About this Blogger RSS

Subscribe

Sign up now and get the best business technology insights direct to your inbox.

  • Daily Edge
  • CTO Edge Update
  • Business Tools & Templates
  • Aligning IT & Business Goals
  • Maximizing IT Investments

1

GRCS: What's in a Name?

Posted by Lora Bentley Jul 31, 2009 10:06:59 AM

It's funny how the labels we use for things change over time. The things we're describing don't really change, but how we describe them does. A pocketbook became a purse and then, in some circles, is now just "a bag."

 

A few years ago, we talked about application service providers; now it's all about software-as-a-service. Terminology comes in and goes out of fashion almost as swiftly as clothes and accessories do.

 

The focus of this blog, governance, risk and compliance (GRC) is no exception. Three years ago I covered compliance. Compliance then morphed into risk management, and then into GRC. Now, Bloor Research's Philip Howard is calling for another name change. He's right. It's probably time for the next label.

 

He argues that GRC doesn't really account for external attacks or internal attacks in the form of "fraud, malicious damage or information theft." Why? Howard says, simply, "GRC, treated literally and in its entirety, is too big for most (any) vendors to handle, so they've cut it down into silos that they can treat."

 

But we all know that silos are bad when it comes to IT. So Howard suggests that GRC should instead be called GRCS, or Governance, Risk, Compliance and Security. It makes sense to me, because GRC and security have been inextricably intertwined from day one. Why not treat security in the same "bundle"? I'm interested to see Howard develop his take on the subject in the days to come

Add a comment Leave a comment on this blog post.
Aug 2, 2009 11:18 AM Guest Marcia E  says:

Interesting thought, but I wonder if this doesn't lump stuff together at the risk of diluting the point of Data Governance? Compliance, risk and security has to do with protection of the data - things on the "must do" list. However,  data governance has, from a business sense, has a ton to do with data quality too - that is making sure that the data is fit for use. Better protection may be a piece of it, but more effective marketing, better customer service, etc. are perhaps an even more important aspect for governance.

There's a new white paper I read recently that points out that, while all the news is about data protection, there are issues with over-limiting access to data too. You can check it out:

 

http://viewer.bitpipe.com/viewer/viewDocument.do?accessId=10142390

 

If we lose sight of data governance as a way to make data more effective, we risk losing sight of these types of concerns, and we lose a lot.

Lowering Your IT Costs with Oracle Database 11g Release 2

This white paper identifies the key capabilities a database management solution needs to successfully deliver more information with higher quality of service, make more efficient use of IT budgets, and reduce the risk of change in data centers.

Software Forum: Information On Demand Virtual Experience

This interactive virtual forum presents leading IT experts providing the insights you need to turn your information into a strategic driver for innovation, business optimization and competitive differentiation.

Data Management

Data management tips and techniques that insure ease of access, comprehensive security and absolute privacy for your invaluable company information.

Virtualization & Business Continuity

Virtualization solutions, management tips and industry insights to promote and insure the lifespan of your business.

Security SaaS Solutions

Hosted security solutions that not only protect your data, but reduce your security management TCO, as well.

Applications for Mid-size Businesses

Applications that mid-sized businesses can use to improve operational efficiency, accelerate growth, and maintain profitability.

Strategic IT Planning & Governance Best Practices Guide

Use this guide — along with the more than 60 templates included — to ensure the overall success of your entire IT department.

Learn more >

All About Reducing Your IT Costs

Looking to cut costs? Use this research-driven Excel tool to pinpoint which IT cost reduction measures best fit your needs.

Learn more >