You are here

Mitigating risks with operational controls

8 September, 2015 - 16:42

Even the authors sometimes wonder about the true distinction between management and operational controls. The easiest way to think about it is that management control functions are performed by managers and operational controls are performed by operators. However, if you look at real organizations, the distinctions between operations staff and management may not be all that clear. Nonetheless, we will use the categories because that is they do reflect the terminologies that one commonly finds in both the trade and academic literature. Three operational controls commonly associated with maintaining system availability are:

  • System monitoring and incident response
  • Performing system backups
  • Planning for disaster recovery

The careful reader will have noticed that these processes do not really help avoid system failures. Good catch! We hope that you will have noted that it is impossible to totally avoid system failures. Despite an organization's best efforts, sometimes things just go wrong. These processes are primarily intended to minimize the adverse consequences that can result if and when things do go wrong.