<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>ESRM on Andrew Sheves</title><link>https://andrewsheves.com/tags/esrm/</link><description>Recent content in ESRM on Andrew Sheves</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sat, 30 Jun 2018 00:00:00 +0000</lastBuildDate><atom:link href="https://andrewsheves.com/tags/esrm/index.xml" rel="self" type="application/rss+xml"/><item><title>Risk management and the security manager – a quick note</title><link>https://andrewsheves.com/2018/06/30/risk-management-and-the-security-manager-a-quick-note/</link><pubDate>Sat, 30 Jun 2018 00:00:00 +0000</pubDate><guid>https://andrewsheves.com/2018/06/30/risk-management-and-the-security-manager-a-quick-note/</guid><description>&lt;p&gt;&lt;em&gt;This post originally appeared on Quora in answer to the question “How does risk management fit in security risk management profession?” &lt;a href="https://www.quora.com/How-does-risk-management-fit-in-security-risk-management-profession/answer/Andrew-Sheves-2"&gt;Link&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="how-does-risk-management-fit-in-security-risk-management-profession"&gt;How does risk management fit in security risk management profession?&lt;/h2&gt;
&lt;p&gt;Ideally, a security manager will use a risk management foundation for their security management system.  This will help integrate security risks into the organization’s understanding of its overall risk environment.  This focus also ensures that the security program is focussed on protecting the organization’s objectives which aligns with the ISO definition of risk:&lt;/p&gt;</description></item></channel></rss>