Title: Presentation
1Presentation 3 Risk Treatment for Microsporum
Todays Discussion Effective use of terbinafine
for the risk treatment of microsporum canis
infections in a feline model Moderator Gerry
Weeks
2IT Risk Management Framework
- Gerry Weeks
- IT Risk Management
- Blue Cross Blue Shield of Minnesota
3Blue Cross Blue Shield of Minnesota
- An independent licensee of the Blue Cross and
Blue Shield Association - Headquartered in Eagan, Minnesota
- Oldest and largest health coverage carrier in
the state - 2.7 million subscribers
- 4,000 employees
- 7 billion in revenues (2005)
4Blue Cross Blue Shield of Minnesota
- Health Coverage, Health Improvement, Medicare,
etc. - Claims, Membership, Portals, etc.
- Federal, State, etc
- HIPAA, DOC, NCQA, AG, NAIC, Internal Controls
over Financial Reporting (SOX 401- based)
5Enterprise Risk Management
COSO Cube
6How?
7IT Risk Management
Slice
COSO Cube
8IT Risk Management Framework
9IT Risk Management Framework
10IT Risk Management Framework
- Philosophy
- Risk has both positive and negative outcomes
- Managing risk is everyones responsibility
- Appetite
- Conservative
- Common Language
- Framework, Dictionary, Bibliography
- IT Risk Management Team
- Tools, Techniques, Monitor, Reporting
11IT Risk Management Framework
- Classification Ownership
- Classification
- - Strategic/Emergent
- - Infrastructure
- - Application
- - Information Assets
- - Projects
- - IT Service Continuity
- - Service Providers Vendors
- Accountability
- - VP Level
- Views Techniques
- Point of View
- - Objectives
- - Threats
- - Vulnerabilities
- - Assets
- Techniques
- - Event analysis
- - Threat modeling
- - Vulnerability analysis
- - Scenarios, Brainstorming, etc
12IT Risk Management Framework
Establish Risk Context
Assess Risks
13IT Risk Management Framework
Analyze Risks
Evaluate Risks
14IT Risk Management Framework
15IT Risk Management Framework
Analyze Risks
Evaluate Risks