Skybox Security, Inc. has published a best practices guide for the planning and implementation of a proactive IT SRM program.
The SRM Blueprint aims to help organisations transform their point-level security programs into a cohesive decision support and analysis program and reclaim millions of dollars annually as the result of inefficient IT risk management practices. Organisations can now identify where they are in the maturity continuum where they want to go and the practical steps necessary to get there.
The SRM Blueprint is written for the Chief Information Security Officer (CISO) and head of IT Operations who are responsible for the resources, processes and goals of their respective organisations. These organisations are focused on IT security risk assessment and management, vulnerabilities mitigation, enforcement of network availability and security policy, and change management. The guidance contained within the SRM Blueprint is vendor-neutral and organised in five (5) sections:
SRM Blueprint Market Drivers and Benefits
  IT security remains the great unknown. Point-level security tools generate an overwhelming amount of data, numerous false positives and lack actionable intelligence.
As a result, the industry often hears the common phrase: You cant manage what you cant measure. The desire to measure IT security effectiveness is driving many organisations to elevate their reactive approach to one that is more proactive. This includes the ability to predict future problems as well as identify root causes driven by a continuous and measurable process. By doing so, organisations can prepare for and respond to threats and policy violations in a calm and rational manner while determining the most effective action items for the elimination of the exposure.
Whats been missing is a Security Risk Management blueprint that defines IT SRM as a best practice. By reading adopting the SRM Blueprint, organisations will understand the steps necessary to transition existing security programs from a reactive to a more proactive practice, enabling them to achieve the following benefits:
Skybox has launched a new consulting service that will assist organisations and government agencies to perform gap analysis of their current SRM program. By doing so, the organisation can develop a roadmap for the implementation of SRM best practices based on their priorities.
A free Managers Guide to the SRM Blueprint is available at the link below.
[Whereas what Skybox say in their blueprint is undoubtedly correct I don't understand what leads them to the conclusion that this is not already being done. Applying metrics and maturity models to risk management is nothing new, nor is operating corporate security within well-defined architectures. All the large consulting companies advice on these things, and authors are constantly publishing papers about them in ISB. Best practices are constantly being developed and progressed. --Ed].
Related links: (Open in a new window.)
  www.skyboxsecurity.com
Taken from Information Security Bulletin.