Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!

Sponsored Content

What is Enterprise Security Risk Management (ESRM) and How Can Your Organization Benefit From Taking This Approach?

900x550_G4S_ESRM_0000_Enterprise_Security_Risk_Management.jpg
March 2, 2020

Enterprise Security Risk Management (ESRM) is a strategic approach to security management that ties an organization’s security practice to its overall strategy using globally established and accepted risk management principles. ASIS International launched a guideline to ESRM in 2019 that explains in detail how that strategic approach works and how to implement it. You can access information about that guideline here 

This article will serve as the foundation for the Security Magazine InfoCenter on ESRM. The InfoCenter will focus on why security organizations should embrace the risk-based approach to security that ESRM codifies. We will also explore different aspects of ESRM, and strategies for implementing and supporting a risk-based approach to security in your organization.

Content Provided By G4S

The heart of ESRM and the key to gaining the business benefits of taking a risk-based approach to security is that the security professionals and the asset owners share security responsibilities. Even though all final security decisions are the responsibility of the asset owner, the people whose assets are being protected and who, as the owners of the exposure usually also own the budget to protect the assets. With that key focus in mind, this article frames the underlying philosophy of ESRM that we will assume through all of the material in this infocenter.

 

What Drives ESRM?

ESRM is partnership:

  • ESRM recognizes that security responsibilities are shared by both security and business leadership, but that all final security decision making is the responsibility of the business leaders.
  • The role of the security leader in ESRM is to manage security vulnerabilities to enterprise assets in a risk decision making partnership with the organization leaders in charge of those assets.  

ESRM is holistic and inclusive:

  • A mature ESRM program encompasses all aspects of security risk mitigation practices to prevent security risk impacts to the enterprise. ​
  • Value exists because the business owns the security risk. Therefore, we now provide business deliverables.

ESRM is participation:

  • Managing the security decision-making process requires:
    • ​Educating business partners on their risk exposures.
    • ​Presenting potential security strategies to protect assets.
    • ​Implementing​ the business leader’s ​decision.
    • Documenting the residual risk and continuing to educate your business partners.

 

What Is ESRM?

The risk-based approach to managing security programs is based on the idea that you cannot protect what you do not understand. Understanding your organization, its mission, its needs and its priorities is the essence of the ESRM life cycle.

We are asking these questions of the business:

What do I need to protect?

What do I need to protect it from?

How can I best and most efficiently protect it?

 

Those questions can be answered by following the steps of the ESRM Life Cycle:

The ESRM Lifecycle

  • Identify and Prioritize Assets: The process of identifying, understanding and prioritizing the enterprise’s assets.
  • Identify and Prioritize Risks: Identifying, understanding, and prioritizing the security risks to the enterprise and their relationship to the assets value.
  • Mitigate Prioritized Risks: Taking the necessary, appropriate and realistic steps to protect against the most serious security threats and risks.
  • Continuous Improvement: The risk paradigm of managing security risks is a cyclical approach to continuously improve and advance the security posture of the enterprise.

If we keep those three basic business questions in mind, everything we do in our security programs will tie together in a chain of value to the business. Any activity we perform in security will be performed in response to an identified risk, all of our risks are tied directly to our critical assets and the value of the program is in ensuring that the organization does not experience harm to or loss of those assets that cause unacceptable hardships to the business.

KEYWORDS: asset protection enterprise risk management ESRM risk management security budget

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Columns
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
  • The Most Influential People in Security 2025

    Security’s Most Influential People in Security 2025

    Security Magazine’s 2025 Most Influential People in...
    Most Influential People in Security
    By: Security Staff
Manage My Account
  • Security eNewsletter & Other eNews Alerts
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

  • Charlotte Star Room
    Sponsored byAMAROK

    In an Uncertain Economy, Security Is a Necessity - Not an Afterthought

  • Sureview screen
    Sponsored bySureView Systems

    The Evolution of Automation in the Command Center

Popular Stories

The Lourve

The Lourve Heist: What Was the State of the Museum’s Security?

critical event management

Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

Office supplies

Security Leaders Share Why 77% Organizations Lose Data Due to Insider Risks

American Airlines

Security Leaders Discuss Cyberattack on American Airlines Subsidiary

Going Down with the Ship

Going Down with the Ship

Top Cybersecurity Leaders

Events

September 18, 2025

Security Under Fire: Insights on Active Shooter Preparedness and Recovery

ON DEMAND: In today’s complex threat environment, active shooter incidents demand swift, coordinated and well-informed responses.

November 13, 2025

Inside the 2025 Security Benchmark Report

The 2025 Security Benchmark Report unveils the top trends CSOs and enterprise security executives are facing in today’s current climate and how each of these trends could potentially impact the enterprise’s global reputation with the public, governments, and business partners. 

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • eNewsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing