Black Hat 10: How PayPal Minimizes GRC Risks | CIO Insight

Black Hat 10: How PayPal Minimizes GRC Risks

Written By
Sean Martin
Sean Martin
Jul 30, 2010
2 minute read

Organizations typically pursue the implementation of a Governance, Risk, and Compliance (GRC) program through a circular series of activities:

  1. Embracing standards and defining policies
  2. Running tests and validations against those policies
  3. Uncovering and classifying ‘issues,’ prioritizing and fixing some of those issues based on risk/impact guesses
  4. Doing it all again in hopes that the state of compliance and risk level stayed at least as good as it was the last time around

This method produces results demonstrating a point-in-time state, but it does little to measure the real risk to the business. If the organization is mature in its implementation, executives may be able to roll some of their findings into the next iteration in order to improve results. If the firm is really on top of its game, executives may be able to analyze multiple iterations to identify trends or patterns, which can be used to further adjust future program activities.Even with relevant trends and patterns emerging, however, those results are based on limited, isolated data and can only be measured against previous results; the analysis does little more than prove that the organization is doing better, or worse, than in the previous period.

In an attempt to help organizations improve their risk management programs, Allison Miller, Group Product Manager, Account Risk at eBay’s PayPal, and Alex Hutton, Principal in Research & Risk Intelligence with Verizon Business, jointly noted that both collaborative information sharing and measurable information analysis are critical aspects of a successful risk management program. During their panel session, "Ushering in the Post-GRC World: Applied Threat Modeling," at the BlackHat USA 2010 Security Conference in Las Vegas July 24-27, 2010, Miller and Hutton discussed the need to close the gap between information security assessments and information security defenses.

CIO Insight Logo

CIO Insight offers thought leadership and best practices in the IT security and management industry while providing expert recommendations on software solutions for IT leaders. It is the trusted resource for security professionals who need to maintain regulatory compliance for their teams and organizations. CIO Insight is an ideal website for IT decision makers, systems integrators and administrators, and IT managers to stay informed about emerging technologies, software developments and trends in the IT security and management industry.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.