Responding to anomalies
Regardless of stringent security controls, an organization will always have some issues and exceptions. The goal of a risk practitioner is to ensure that sufficient controls are put in place and procedures are developed in the case of an issue or exception that might pose a risk. For instance, an organization may have implemented an overarching policy of disabling USB access for all employees, but it may be required by the sales team to show a demo of an application or the developers to run a code snippet and perform thorough testing. In those cases, the risk manager should strive to balance such one-off cases by defining a mechanism to manage these requests. In the following section, we will review a few ways to manage these issues, findings, and exceptions.
Managing issues, findings, and exceptions
The following are a few formal approaches to managing issues, findings, and exceptions:
- Configuration management: Configuration management requires...