The latest enterprise risk management news from around the world

Enterprise security risk management guidance launched by ASIS

ASIS International has published a new guidance document for enterprise security risk management (ESRM), claimed to be the first strategic security management tool of its kind, ‘elevating the security function by establishing a partnership between security professionals and business leaders to manage security risks’.

According to ‘Enterprise Security Risk Management Guideline’, the objective of ESRM is to identify, evaluate, and mitigate the likelihood and/or impact of security risks to the organization with priority given to protective activities that help enable the organization to advance its overall mission. ESRM positions the security professional as a trusted advisor to help guide asset owners through the process of making security risk management decisions.

“We’re very proud to provide this foundational tool to ASIS members—and the security industry at-large—to help guide them through adoption of ESRM within their organizations” said David R. Feeney, CPP, PMP, Chairman of the ASIS ESRM Guideline Technical Committee.

ESRM recommends that security professionals maintain an understanding of the organization’s overall strategy, including its mission and vision, core values, operating environment, and stakeholders. Understanding this context will enable security professionals to effectively support and align with the organization’s strategic goals.

The guidance outlines how the ESRM Cycle is built on a foundation of transparency, governance, partnership with stakeholders, and holistic risk management. By continually repeating the ESRM Cycle, security professionals can bring ESRM practice to maturity and maintain high performance over time.

“We remain committed to the global development of ESRM, and the release of our ESRM Guideline demonstrates the ASIS Board of Director’s ongoing support to formalize ESRM globally,” said Tim McCreight, ASIS Global Board sponsor of the ESRM Initiative.

More details.



Want news and features emailed to you?

Signup to our free newsletters and never miss a story.

A website you can trust

The entire Continuity Central website is scanned daily by Sucuri to ensure that no malware exists within the site. This means that you can browse with complete confidence.

Business continuity?

Business continuity can be defined as 'the processes, procedures, decisions and activities to ensure that an organization can continue to function through an operational interruption'. Read more about the basics of business continuity here.

Get the latest news and information sent to you by email

Continuity Central provides a number of free newsletters which are distributed by email. To subscribe click here.