ASIS International ESRM Slideshow PDF
ASIS International ESRM Slideshow PDF
ASIS International ESRM Slideshow PDF
The ESRM strategic initiative is well under way and will publish
official trainings and other documents in the coming months.
In the meantime, the below information explains the goals of the
workstreams as well as a high level presentation defining ESRM
and its importance.
A S I S P R O G R A M U P D AT E
ESRM DNA
Internal and External ESRM Marketing /
Communications / Branding
If your Council or Chapter would like to hear more about ESRM messaging, please reach
out to Tim Wenzel, CPP and Ray O’Hara, CPP at [email protected].
ENTERPRISE SECURITY RISK
MANAGEMENT
9
ESRM DEFINED
Enterprise Security Risk Management (ESRM) is a
strategic security program management approach that ties
an organization’s security practice to its mission and goals
using globally established and accepted risk management
principles.
SECURITY IS ABOUT RISK MANAGEMENT
ESRM recognizes that security responsibilities are shared by both security and
business leadership, but that all final security decision making is the responsibility
of the business leaders. The role of the security leader in ESRM is to manage
security vulnerabilities to enterprise assets in a risk decision making partnership
with the organization leaders in charge of those assets.
Managing the security decision making process requires:
• Educating internal business partners on the realistic impacts of security risks to
assets under their control.
• Presenting potential security strategies to decision-making business leaders to
mitigate those impacts.
• Enacting the business leader’s security risk mitigation choice, driven by
business risk tolerance.
11
W H AT I S E S R M ?
W H AT E S R M I S N ’ T
REFERENCES
• ISO/Guide 73:2009(en) - Risk management. https://www.iso.org/obp/ui/#iso:std:iso:guide:73:ed-1:v1:en
• ISO 704, Terminology work — Principles and methods
• ISO 860, Terminology work — Harmonization of concepts and terms
• ISO 3534-1, Statistics — Vocabulary and symbols — Part 1: General statistical terms and terms used in
probability
• ISO 9000, Quality management systems — Fundamentals and vocabulary
• ISO 10241, International terminology standards — Preparation and layout
• ISO 31000:2009, Risk management — Principles and guidelines
• ISO/IEC Guide 2, Standardization and related activities — General vocabulary
• ISO/IEC Guide 51, Safety aspects — Guidelines for their inclusion in standards
18