Is the cloud the next stop for enterprise risk management?

 

Connecting state and local government leaders

Cloud-based governance, risk and compliance solutions are a logical step for agencies that need to address new rules, consolidate systems and serve their mobile workforce.

Could enterprise risk management become a common cloud-based service at most government agencies? It's an idea being explored by other industries, especially within the financial management and manufacturing sectors. There's a good chance that the idea could take root in the public sector too.

Once an organization assesses its potential safety and economic risks, specific rules can be then be set to help mitigate those risks. Historically organizations have not always taken  an enterprisewide approach to risk management. More often solutions were done piecemeal, such as requiring locks on certain doors or passwords on specific machines. As risk management became more formalized, it slowly became an evaluation process to be followed, a set of formal decisions to be made and a way to track and enforce specific rules. 

A risk-management system often is used not only to track risk but to document decisions made on how the risk should be addressed. This system can include coordinating resources to minimize risk, monitoring risk-related activity, and managing the short- or long-term impact of known risks. 

Such systems fall under the general heading of governance, risk and compliance (GRC), and many government agencies already have systems in place to help them manage their approach to risk. The key word here, though, is "systems" (plural). Agencies can find it difficult to integrate a truly enterprisewide view of how risk is managed. Too often GRC systems have been built ad-hoc at the sub-agency level to deal with local issues. 

Further, government has unique needs. Risk management is not the same for government as it is for an insurance company that is working to manage risk and assure profits across thousands of insurance policies and investments. Government also tends to focus heavily on risk associated with project management. Getting program or project governance properly aligned helps ensure success for the program itself, and it also reduces long-term risk from other internal and external factors. 

There are popular GRC solutions available from enterprise software vendors such as Oracle and SAP. Some organizations have created their own customized risk-management solutions, and other companies have risk-management solutions that are targeted at a specific issue, such as compliance with the Federal Information Security Management Act or the Homeland Security Presidential Directive (HSPD) 12.

We've also seen compliance monitoring and enforcement systems that address data privacy, cyber-threat protection, configuration management rules and monitoring as well as network monitoring. The Federal CIO Council even mentioned these types of systems as leading priorities for 2014. Individual government lines of business are influencing an ever greater number of investment decisions related to GRC initiatives.

So there's a critical mass of interest in these types of solutions. That’s because agencies are under pressure to take an enterprisewide approach to GRC. They need to upgrade systems in order to make that happen, and there are always new rules hitting them that affect what their risk-management systems must track. In fact, big data and analytics draw the most attention for risk and innovation, and both are key expansion areas for government agencies. Meanwhile, we have an increasingly mobile workforce and onset of new cyber threats. Thus, security and risk has become a key government business function that relies on technology as a cornerstone to its success.

Cloud-based GRC solutions are a logical step for agencies that need to address new rules, consolidate systems and serve their mobile workforce. Most enterprise software vendors offer cloud-hosted versions of their risk management solutions, and it's worth talking to them to see if this is a logical place for an agency to migrate. 

Government can offer help too. Last year the National Institute of Standards and Technology published a Draft Cloud Computing Security Document that  introduced a "cloud-adapted Risk-Management Framework for applications and/or services migrated to the cloud." Back in 2010 NIST also established a guide for applying the  Risk-Management Framework to federal IT systems. GSA also offers a set of solutions under a blanket purchase agreement related to Risk-Management Framework and associated services (though it's not clear how much of this is available via cloud.)

What all of this means is that there is a growing focus on risk-management solutions in general — and GRC solutions in particular. It can be difficult for agencies to tackle all that is required for compliance, while still meeting the needs of their mobile workforce. Cloud solutions seem to offer the best potential right now, but they may not offer total compatibility with all government systems and individual agency requirements. 

But the trend is clear, and taking risk management to the cloud should definitely be part of the discussion at most agencies. 

X
This website uses cookies to enhance user experience and to analyze performance and traffic on our website. We also share information about your use of our site with our social media, advertising and analytics partners. Learn More / Do Not Sell My Personal Information
Accept Cookies
X
Cookie Preferences Cookie List

Do Not Sell My Personal Information

When you visit our website, we store cookies on your browser to collect information. The information collected might relate to you, your preferences or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. However, you can choose not to allow certain types of cookies, which may impact your experience of the site and the services we are able to offer. Click on the different category headings to find out more and change our default settings according to your preference. You cannot opt-out of our First Party Strictly Necessary Cookies as they are deployed in order to ensure the proper functioning of our website (such as prompting the cookie banner and remembering your settings, to log into your account, to redirect you when you log out, etc.). For more information about the First and Third Party Cookies used please follow this link.

Allow All Cookies

Manage Consent Preferences

Strictly Necessary Cookies - Always Active

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data, Targeting & Social Media Cookies

Under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information to third parties. These cookies collect information for analytics and to personalize your experience with targeted ads. You may exercise your right to opt out of the sale of personal information by using this toggle switch. If you opt out we will not be able to offer you personalised ads and will not hand over your personal information to any third parties. Additionally, you may contact our legal department for further clarification about your rights as a California consumer by using this Exercise My Rights link

If you have enabled privacy controls on your browser (such as a plugin), we have to take that as a valid request to opt-out. Therefore we would not be able to track your activity through the web. This may affect our ability to personalize ads according to your preferences.

Targeting cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Social media cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools.

If you want to opt out of all of our lead reports and lists, please submit a privacy request at our Do Not Sell page.

Save Settings
Cookie Preferences Cookie List

Cookie List

A cookie is a small piece of data (text file) that a website – when visited by a user – asks your browser to store on your device in order to remember information about you, such as your language preference or login information. Those cookies are set by us and called first-party cookies. We also use third-party cookies – which are cookies from a domain different than the domain of the website you are visiting – for our advertising and marketing efforts. More specifically, we use cookies and other tracking technologies for the following purposes:

Strictly Necessary Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Functional Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Performance Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Social Media Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Targeting Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.