Skip to content
Artwork for The ITSM Practice: Elevating ITSM and IT Security Knowledge
The ITSM Practice: Elevating ITSM and IT Security Knowledge · Tuesday · 19 min

Should Your CMDB Know Your Business Risk?

A critical vulnerability is not automatically a critical business risk. If your CMDB only tells you which server is affected but not the customer, service, contract, SLA, or revenue behind it, you are missing the information that matters. This episode explains why CISOs need a business-aware CMDB to connect technical risk with real business impact. In this episode, we answer to: Can your CMDB tell the CISO what a security incident actually means for the business? How do you prioritize vulnerabilities based on customers, SLAs, contracts, and revenue at risk? Why is connecting CMDB, ITSM, CRM, and ERP data critical for risk-based security decisions? Resources Mentioned in this Episode: PeopleCert website, course "ITIL 4 Practitioner: Service Configuration Management", link https://www.peoplecert.org/browse-certifications/it-governance-and-service-management/ITIL-1/itil-4-practitioner-service-configuration-management-3800 PeopleCert website, case study "SITA", link https://www.peoplecert.org/-/media/folders-reorganized/pdfs/itil-maturity-model/cs-sita.pdf ServiceNow website, guide "CMDB Design Guidance", link https://www.servicenow.com/content/dam/servicenow-assets/public/en-us/doc-type/resource-center/white-paper/wp-cmdb-design-guidance.pdf BMC website, article "Best Practices for the Common Data Model", link https://docs.bmc.com/xwiki/bin/view/Service-Management/IT-Service-Management/BMC-Helix-CMDB/ac254/Managing-the-common-data-model/Best-Practices-for-the-Common-Data-Model/ Device42 website, article "CMDB Architecture Best Practices: Aligning Design with IT Objectives", link https://www.device42.com/cmdb-best-practices/cmdb-architecture/ Device42 website, guide "The Technical Guide to CMDB Best Practices", link https://www.device42.com/cmdb-best-practices/ Connect with me on: LinkedIn: https://www.linkedin.com/in/theitsmpractice/ Website: http://www.theitsmpractice.com And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security. Credits: Sound engineering by Alan Southgate - http://alsouthgate.co.uk/ Graphics by Yulia Kolodyazhnaya

0:00-19:34

transcript

No transcript — this publisher did not publish one.

show notes

A critical vulnerability is not automatically a critical business risk. If your CMDB only tells you which server is affected but not the customer, service, contract, SLA, or revenue behind it, you are missing the information that matters. This episode explains why CISOs need a business-aware CMDB to connect technical risk with real business impact.


In this episode, we answer to:

Can your CMDB tell the CISO what a security incident actually means for the business?

How do you prioritize vulnerabilities based on customers, SLAs, contracts, and revenue at risk?

Why is connecting CMDB, ITSM, CRM, and ERP data critical for risk-based security decisions?


Resources Mentioned in this Episode:

PeopleCert website, course "ITIL 4 Practitioner: Service Configuration Management", link https://www.peoplecert.org/browse-certifications/it-governance-and-service-management/ITIL-1/itil-4-practitioner-service-configuration-management-3800


PeopleCert website, case study "SITA", link https://www.peoplecert.org/-/media/folders-reorganized/pdfs/itil-maturity-model/cs-sita.pdf


ServiceNow website, guide "CMDB Design Guidance", link https://www.servicenow.com/content/dam/servicenow-assets/public/en-us/doc-type/resource-center/white-paper/wp-cmdb-design-guidance.pdf


BMC website, article "Best Practices for the Common Data Model", link https://docs.bmc.com/xwiki/bin/view/Service-Management/IT-Service-Management/BMC-Helix-CMDB/ac254/Managing-the-common-data-model/Best-Practices-for-the-Common-Data-Model/


Device42 website, article "CMDB Architecture Best Practices: Aligning Design with IT Objectives", link https://www.device42.com/cmdb-best-practices/cmdb-architecture/


Device42 website, guide "The Technical Guide to CMDB Best Practices", link https://www.device42.com/cmdb-best-practices/


Connect with me on:

LinkedIn: https://www.linkedin.com/in/theitsmpractice/

Website: http://www.theitsmpractice.com

And if you want more tips and guidance, follow me on LinkedIn. I am sharing daily posts regarding Enterprise Service Management, IT Service Management, and IT Security.


Credits:

Sound engineering by Alan Southgate - http://alsouthgate.co.uk/


Graphics by Yulia Kolodyazhnaya