Petruzzi John, Loyear Rachelle
Time Warner Cable, 60 Columbus Circle, 9th Floor - TWC Security, New York, NY 10023, USA.
J Bus Contin Emer Plan. 2016;10(1):44-56.
Enterprise Security Risk Management (ESRM) is a new philosophy and method of managing security programmes through the use of traditional risk principles. As a philosophy and life cycle, ESRM is focused on creating a business partnership between security practitioners and business leaders to more effectively provide protection against security risks in line with acceptable risk tolerances as defined by business asset owners and stakeholders. This paper explores the basics of the ESRM philosophy and life cycle and also shows how embracing the ESRM philosophy and implementing a risk-based security management model in the business organisation can lead to higher levels of organisational resilience as desired by organisation leaders, executives and the board of directors.
企业安全风险管理(ESRM)是一种通过运用传统风险原则来管理安全计划的新理念和方法。作为一种理念和生命周期,ESRM专注于在安全从业者和企业领导者之间建立业务伙伴关系,以便根据业务资产所有者和利益相关者所定义的可接受风险容忍度,更有效地防范安全风险。本文探讨了ESRM理念和生命周期的基础知识,还展示了在商业组织中接受ESRM理念并实施基于风险的安全管理模型如何能够如组织领导者、高管和董事会所期望的那样,提高组织的恢复力水平。