It can be difficult to allocate responsibilities in risk management. In practice, especially in the case of information security risks, people often refer to the CISO or the Security Officer, and if there is no such position, the focus will shift to the IT Manager or CIO. The Three Lines of Defence model (3LOD), or nowadays simply the Three Lines Model, provides a framework for company-wide risk management structures. It helps in allocating roles and responsibilities and aims to create insight into how the organisation is “in control” in terms of risk management.
Understanding risks at the right level requires reporting according to the requirements of the different levels and, above all, clear responsibilities at each level. Taking the specific information security process as an example, the three lines of this model can be described in the following simplified terms:
This model ensures that risks are allocated to the right level and that they are controlled in an adequate manner. This, then, is also the basis for sound (and comprehensive) reporting.
We have used the Three Lines Model for various companies in setting up their IT Risk Management. These companies ranged from small businesses to listed companies and we always started with the premise that gaining an understanding of the risks was the goal. Aiming for the measures to be completely effective does not give a company the right tools to take steps in risk management; aiming for a complete understanding of the risks and the status of the measures does. The Three Lines Model helps you to allocate responsibilities correctly and to define the reporting structure.
Please feel free to contact us via sales@cuccibu.nl We would be happy to help you find the solution that best suits your company’s needs.