Next meeting
| Date |
12 June 2013 |
| Time |
10.45 - 15.30 |
| Location |
TBC
|
| Topic |
"Culture, Awareness and Training - Making it Stick" |
| Agenda |
Full agenda TBC |
Future meetings
| Date |
Topic |
| 5 September |
Data Protection - Incorporating the new EU Data Privacy Proposals |
| 23 October |
TBC |
| 11 December |
TBC |
Group aims & objectives
The Risk in Information Systems and E-business (RISE) is being re-launched with an emphasis on understanding the risks associated to all aspects of technology, change, security and impact on the front end business risk. The aim of the Group is to bring together risk professionals, students and those with an interest in this area together to share best practice, experience and build an informal network to discuss issues and challenges both internally and externally within their respective organisations. It is the aim of the group to bring together professionals from a wide range of industries and expertise to enrich the debate around technology risk. The inaugural meeting will set the agenda for the SIG but it is expected the group will meet on a quarterly basis with a mixture of talks from Industry experts and practitioners, round table’s on specific issues and debates where differing points of view will be advocated by two parties to facilitate a discussion. Some of the topics suggested for discussion include:
- Data Loss, Is it important ?
- Cyber Crime, is this the biggest threat to companies, economies and countries ?
- What’s the role of the IT Risk Manager within different industries ?
- What does the Cloud mean for companies and the risk profession ?
- What’s the industry standard for the management and delivery of IT Change ?
- How can you minimise the potential for Fraud within systems ?
- Does regulation dictate IT design or does business process ?
- PCI DSS, does it matter ?
- Data privacy legislation, regulation, coverage and approaches
- Social Media, the Internet and Data Privacy ?
Research Paper
The group is currently conducting a valuable piece of thought leadership into the fast paced and dynamic Cyber Threats to business, governments and global enterprises in the name of the IRM. This research is aimed at giving Risk Managers and senior boards some practical guidance and advice in assessing, managing and monitoring cyber exposures and attempting to demystify some of the multiple messages around the subject matter.
The research is covering the following chapters:
• Definition of Cyber risk – IET leading - Hugh Boyes
• Tools and models for assessment of Cyber exposures
• Reaction, resilience and incident management
• Interpretation and understanding of the multiple standards – IS27001 etc
• Behaviour, and the impact of Social Media – Aviva leading – Dave Canham
• Opportunties associated to “Cyber”, it’s not all bad? BAE Deltica
• Information Security and the Cloud – Crowe Howarth - Dan Roberts
• Supply Chain, process outsource – Zurich leading - Alastair Allison
• Insurance for Cyber – AIG leading – Jamie Bouloux
• Iceberg impact of a cyber loss – TNT leading – Matthew Hillyer
• Skills, training and capability
• Investment case for “Cyber”
• Reputation, brand and corporate response - (Crowe Howarth - Dan Roberts 2nd)
• Incident Management - (Aviva 2nd)
• Mobile device security - (Zurich 2nd)
If you would like to lead the development of any of the available chapters above (including those listed as 2nd), or if you wish to contribute to any of the chapters listed please contact any one of the committee members to discuss how you can support.
You may also be interested in the work currently being conducted by the Governance, Risk and Compliance Special Interest Group.
Recent meetings
| Date |
17 April 2013 |
| Location |
Aviva Plc, Fenchurch Street, London
|
| Topic |
Board Engagement in Information Security
Presentation to follow |
| Date |
22 February 2013 |
| Location |
Aviva Plc, Fenchurch Street, London
|
| Topic |
"Cyber" - A threat, an opportunity, or the voyage into the unknown?
Presentation to follow |
| Date |
17 August 2012 |
| Location |
Crowe Clark Whitehill Offices, London |
| Topic |
11.00 – 11.30 Introduction and recap – Dave Canham (Avvia)
11.30 - 12.30 “Are third parties protecting your data?" - Alastair Allison (Zurich)
The topic looks at how companies can assure themselves that the supply chain is protecting their customer and personal data from malicious and accidental loss
12.30 - 13.00 Break & networking
13.00 – 14.00 COSO & Cloud Computing – Daniel Roberts (Crowe Horwath GRC)
We will take a look at the guidance provided by COSO for Cloud Computing, with a few personal observations and comments on cloud experience.
14.00-14.30 – Survey Results, Close and next meeting. |
| Date |
26 June 2012 |
| Time |
11.00 - 15.30 |
| Location |
DVLA Offices, Swansea |
Programme:
11.00 - 11.30 |
Introduction and recap
Dave Canham (Aviva) |
| 11.30 - 12.30 |
Are third parties protecting your data?
Alastair Allison (Zurich)
|
| 12.30 - 13.00 |
Break and networking |
13.00 - 14.00
Break-out groups |
Olympics Security
- What is your organisational view on the risks posed by the Olympics from a RISE viewpoint, are you worried about Hacking / DOS?
- Are you on increased watch from potential “cyber disruption” ?
- Are you seeing this as an opportunity to test DR and BCM provisions such as the strength of your organisations “working from home” processes?
|
| 14.00 - 15.00 |
Information Assurance at DVLA & Herding Sheep offshore
David Pope (DVLA) |
| 15.00 - 15.30 |
Close and next meeting |
| Date |
1 March 2012 |
| Time |
11.00 - 15.00 |
| Location |
Aviva Insurance UK Ltd
Fenchurch Street
London
EC3M 3LA |
Programme
11.00 - 11.15 |
Arrival and Welcome (Coffee) |
| 11.15 - 11.30 |
Introductions (All Attendees) |
| 11.30 - 12.15 |
Role of the Operational IT Risk Manager within Aviva Speaker: David Canham, MIRM
Aviva UK IT Risk Manager
Download the presentation (PDF 1,308 Kb) |
| 12.15 – 13.15 |
Re-energising RISE. What do we want from this Group. What do we see as the biggest challenges? What would we like to know more about ? (Chair to Introduce, All Attendees to debate)
Download the write-up (PDF 553 Kb) |
| 13.15 - 14.00 |
Lunch |
| 14.00 - 14.45 |
Social Media, the Internet and Data Privacy
Speaker: Wendy Dack (Aviva Group Data Protection and Privacy Manager) |
| 14.45 - 15.00 |
Reflections from the session, topics for next time |
| 15.00 |
Close |
|