Risk Management

Risk management: An inside view

CIA logo

This text is intended to be a caption for the above image.

In a practical as opposed to a theoretical sense, there are pros and cons to the current focus on risk management, said Robert Bigman, who retired as the CIA’s chief information security officer earlier this year and is now CEO of his own consulting firm, 2BSecure LLC.

“I think it has a lot of appeal in government for agencies getting a handle on what they have, though not necessarily where the risk is,” he said. “Most agency CIOs don’t know what they have and what’s connected to what, so in that sense the risk management process is good, not just from an asset management perspective but also for security.”


Main story: Cyber insecurity: Managing against the risks


However, there is no accepted common concept behind what risk management means in the IT environment, Bigman added. Management strategies are good when you have a finite set of variables and know what you are dealing with, but that’s not typical for IT security.

Furthermore, most agencies must take risks every day in order to do their jobs — risks that a risk management strategy will tell you not to take. In that case, he said, what is likely to take precedence?

“Because of the event-by-event, case-by-case state agencies are in, security is a day-by-day, tactical response program, and what we’re doing is running around putting out fires and trying to keep the mission going,” he said. “This notion that you can automate this and interactively understand your risk on a daily basis is a whim, a farce.”

About the Author

Brian Robinson is a freelance writer based in Portland, Ore.

Featured

  • Contracting
    8 prototypes of the border walls as tweeted by CBP San Diego

    DHS contractors face protests – on the streets

    Tech companies are facing protests internally from workers and externally from activists about doing for government amid controversial policies like "zero tolerance" for illegal immigration.

  • Workforce
    By Mark Van Scyoc Royalty-free stock photo ID: 285175268

    At OPM, Weichert pushes direct hire, pay agent changes

    Margaret Weichert, now acting director of the Office of Personnel Management, is clearing agencies to make direct hires in IT, cyber and other tech fields and is changing pay for specialized occupations.

  • Cloud
    Shutterstock ID ID: 222190471 By wk1003mike

    IBM protests JEDI cloud deal

    As the deadline to submit bids on the Pentagon's $10 billion, 10-year warfighter cloud deal draws near, IBM announced a legal protest.

Stay Connected

FCW Update

Sign up for our newsletter.

I agree to this site's Privacy Policy.