Leveraging Technology to Enhance Your Agency’s ERM Capabilities – 2018

In this 2018 Summit presentation… Technology cannot provide an out of the box ERM program, but it can definitely facilitate the process. This session discussed how using technology can jump start your ERM program capabilities, and how these platforms are creating innovative solutions to challenges your ERM program may face through maturity such as risk identification, collection, collaboration, and prioritization.

Speakers: W. Curtis McNeil, AOC; LaTaiga Proctor, Census Bureau
Download

Applying ERM Principles to Functional Divisions: A Federal Grants Risk Management Case Study – 2018

In this 2018 Summit presentation… Today, buzz words like “enterprise risk management” (ERM) and “accountability” abound in the public and private sectors. But how do they really work operationally? Faced with an $11 billion budget for grant programs but finite internal resources to manage them, the Health Resources and Services Administration (HRSA) sought a way to use risk management to improve accountability and oversight of grants. Seeking a risk-based, data driven approach to strategic decisions, HRSA embarked on a one-of-a-kind assessment of current risks and related risk management practices, and the development of risk tools for decision makers.

This presentation provides a case study for operationalizing risk management in the grants world, and more generally at the sub-agency level. Those seeking to integrate risk management into their operations heard about project challenges and successes, key risk findings and recommendations, and considerations when taking on such a project. During the presentation, the speakers:

  • Explained the context within which HRSA determined to launch such an ambitious study, and the questions faced in developing the project;
  • Briefly walked through the tools developed to document and assess key risks and opportunities;
  • Described the findings of the study and how ERM principles were applied; and
  • Discussed the challenges and limitations faced with a risk management study of this kind.

Speakers: Lori Giblin, CNCS; Suzanne Auerbach, HRSA
Download

Shaping the Future Cybersecurity Risk in the Public Sector: A CIO Perspective – 2018

In this 2018 Summit presentation… CIO’s lessons learned in leveraging ERM to mitigate cybersecurity risks, including:

  • Innovative approaches for staying ahead of emerging risks
  • Motivating a risk culture that promotes transparency
  • Integrating risk monitoring with other entities (OIG, OMB, DHS, Board of Directors, others)
  • Best practices for addressing (and mitigating) reputational risks

Speaker: Howard Whyte, Chief Information Officer (CIO) and Chief Privacy Officer (CPO), FDIC
Download

Cyber Risk and the Chief Risk Officer: What CROs Need to Know About the New NIST Risk Management Framework – 2018

In this 2018 Summit presentation… NIST is doing a major upgrade to one of its flagship security guidelines, Special Publication 800-37, the Risk Management Framework (RMF). The updated RMF 2.0, to be published this Fall, will provide many new features for Cyber Risk Officers and Enterprise Risk Management (ERM) programs. In addition to managing security risk, the RMF 2.0 will also address privacy and supply chain risks and the alignment with key constructs in the Cybersecurity Framework (CSF) as part of a comprehensive and unified ERM approach.

Speaker: Ron Ross, NIST
Download

Communicating the Value of ERM, Culture and Governance: The Positive Impacts of ERM on Morale and How to Achieve Sustainable Motivation – 2018

In this 2018 Summit presentation… Over the past decade, the ERM community of practice has been making great strides in implementing ERM in the Federal government. As we sustain and improve upon these ERM programs, we can’t lose sight of the importance of motivation. We need to continue to motivate our risk management practitioners as well as our stakeholders. Hear from government leaders on the attitudes, behaviors, tone at the top and corporate values they use in managing risk and how they communicate the value of ERM, culture and governance to motivate their workforce to continue to implement and improve upon their ERM practices.
Speakers: Jennifer Hills, King County, Washington; Carissa Riddle, HUD
Download

Extended Enterprise Risk Management and the Public Sector – 2018

In this 2018 Summit presentation… Extended enterprise risk management (EERM) is the practice of anticipating and managing exposures associated with third parties across the organization’s full range of operations as well as optimizing the value delivered by the third-party ecosystem. What does third-party risk look like? While one often thinks of data breaches involving IT providers, the tentacles of third-party risk extend into the farthest corners of the extended enterprise ecosystem. Speakers: Jonathan Swanson, Aetna; Jason Leecost, HUD, Ginnie Mae
Download

The Resilient Leader’s Strategies for ERM Success – 2018

In this 2018 Summit presentation… What key milestones make an ERM Implementation Strategy work? In this session, participants learned some of the not-so-conventional methods that has and can be used by resiliency in leadership to ensure the staying power of ERM practices in agencies.  Methods used over the past seven years were shared to shed light on the opportunities and challenges associated with program implementation.  The session discussed methods that address the deliverables in the revised A-123 policy (i.e. risk profile, governance, and integration of ERM and Internal Control) from the Department of Commerce perspective. Speaker: Karen Hardy, DOC
Download