<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Audit Management - DoubleCheck Software</title>
	<atom:link href="https://www.doublechecksoftware.com/category/audit-management/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.doublechecksoftware.com</link>
	<description>Engage Your Enterprise</description>
	<lastBuildDate>Tue, 17 Oct 2023 20:19:33 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.6.5</generator>

<image>
	<url>https://www.doublechecksoftware.com/wp-content/uploads/2018/09/cropped-doublecheck-icon--32x32.png</url>
	<title>Audit Management - DoubleCheck Software</title>
	<link>https://www.doublechecksoftware.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Why Settle For Less? Twenty (20) Elements in a World-Class ERM or GRC Program</title>
		<link>https://www.doublechecksoftware.com/why-settle-for-less-twenty-20-elements-in-a-world-class-erm-or-grc-program/</link>
					<comments>https://www.doublechecksoftware.com/why-settle-for-less-twenty-20-elements-in-a-world-class-erm-or-grc-program/#respond</comments>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Fri, 13 Oct 2023 19:44:51 +0000</pubDate>
				<category><![CDATA[Audit Management]]></category>
		<category><![CDATA[Cyber Security Risk Management]]></category>
		<category><![CDATA[Enterprise Risk Management]]></category>
		<category><![CDATA[GRC Implementation Success]]></category>
		<category><![CDATA[TPRM]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[ERM]]></category>
		<category><![CDATA[erm software]]></category>
		<category><![CDATA[GRC reports]]></category>
		<category><![CDATA[risk register]]></category>
		<category><![CDATA[Third Party Risk Management]]></category>
		<category><![CDATA[TPRM Software]]></category>
		<guid isPermaLink="false">https://www.doublechecksoftware.com/?p=3699</guid>

					<description><![CDATA[<p>A World-Class Enterprise Risk Management (ERM) or Governance, Risk and Compliance (GRC) program offers numerous benefits to organizations of all sizes and across various industries. Here are 20 key elements needed for the creation of an efficient, effective, and successful program: 1. Mission Statement Purposeful connection of strategy and tactics 2. Framework – Part A<a href="https://www.doublechecksoftware.com/why-settle-for-less-twenty-20-elements-in-a-world-class-erm-or-grc-program/">[...]</a></p>
<p>The post <a href="https://www.doublechecksoftware.com/why-settle-for-less-twenty-20-elements-in-a-world-class-erm-or-grc-program/">Why Settle For Less? Twenty (20) Elements in a World-Class ERM or GRC Program</a> first appeared on <a href="https://www.doublechecksoftware.com">DoubleCheck Software</a>.</p>]]></description>
										<content:encoded><![CDATA[<p>A World-Class Enterprise Risk Management (ERM) or Governance, Risk and Compliance (GRC) program offers numerous benefits to organizations of all sizes and across various industries. Here are 20 key elements needed for the creation of an efficient, effective, and successful program:</p>
<p>1. Mission Statement</p>
<ul>
<li>Purposeful connection of strategy and tactics</li>
</ul>
<p>2. Framework – Part A</p>
<ul>
<li>Strategic context (“Who are you and what are you trying to achieve?”)</li>
<li>Without this, there is no reason for ERM or GRC</li>
</ul>
<p>3. Framework – Part B</p>
<ul>
<li>Foundational underpinning (Culture and Governance)</li>
<li>Connective tissue existing between strategy and tactics</li>
<li>Underlying essence; these foundations are in place at all times</li>
</ul>
<p>4. Framework – Part C</p>
<ul>
<li>Tactical Execution (4-Step iterative process: identify, assess, mitigate and monitor)</li>
</ul>
<p>5. Governance Structure</p>
<ul>
<li>Clear-cut roles and responsibilities</li>
<li>Best portrayal: Three lines of defense</li>
</ul>
<p>6. Universe</p>
<ul>
<li>4 categories – 3 common (&#8220;Finance&#8221;, &#8220;Operational&#8221; and &#8220;Strategic&#8221;) and 1 unique (“Core Business”)</li>
<li>Dynamic; encompasses emerging risks</li>
<li>Aligns with always-changing nature of risks themselves</li>
</ul>
<p>7. Rating Scales</p>
<ul>
<li>Understandable</li>
<li>Severity, likelihood, direction and velocity</li>
<li>Inherent and residual</li>
</ul>
<p>8. Policies</p>
<ul>
<li>Major risks (dozen or so)</li>
<li>Each comprised of: definition; goal; roles and responsibilities (1st/2nd/3rd lines); appetite; tolerances</li>
</ul>
<p>9. Language</p>
<ul>
<li>Succinct; simpler is better</li>
<li>Don’t throw in unnecessary phrases (“I was able to…”)</li>
<li>Precise; exact</li>
<li>Iterative; over and over</li>
<li>Powerful</li>
<li>One shot; on the mark; needs to resonate</li>
<li>Use present tense whenever possible (alive, here and now)</li>
<li>Pragmatic (understands dynamics, keeps big picture in mind)</li>
<li>Embedded and actionable</li>
<li>Positive (figure out a way, convince)</li>
<li>Purposeful and insistent</li>
<li>Rigorous and disciplined</li>
<li>Not merely esoteric, hypothetical or academic</li>
<li>Put away the pom-poms; self-praise is no praise</li>
</ul>
<p>10. Reporting</p>
<ul>
<li>Risk arrow heat map</li>
<li>Risk owner report</li>
</ul>
<p>11. Overall Cultural Model</p>
<ul>
<li>Code of ethics</li>
<li>What do your people do when no one is watching?</li>
<li>Behaviors you expect and tolerate</li>
</ul>
<p>12. Risk Culture</p>
<ul>
<li>Shared understanding towards risk</li>
</ul>
<p>13. Deputized Risk Owners</p>
<ul>
<li>Subject matter experts</li>
<li>Hold them accountable</li>
<li>Don’t be afraid to critique or challenge</li>
<li>Ensure that people are not just going through the motions (e.g. no changes year-to-year)</li>
<li>Educate them; understand this is not their day job</li>
<li>Depend upon them, and their perceptions, heavily</li>
<li>You are only as good as what they provide</li>
<li>Be respectful of their time</li>
</ul>
<p>14. Risk Owner Surveys</p>
<ul>
<li>Take the opportunity to ask special, “hot-button” questions each year</li>
<li>Don’t overdo it</li>
</ul>
<p>15. Risk Appetite</p>
<ul>
<li>High, medium, low</li>
<li>Tolerances – exact point at which appetite exceeded</li>
</ul>
<p>16. Configurability</p>
<ul>
<li>Collaborate with a vendor having a matching mindset</li>
</ul>
<p>17. The Fuel of Passion Fuel</p>
<ul>
<li>Get excited and stay excited</li>
<li>How many people have this opportunity?</li>
<li>Keep turning insights into actions</li>
<li>Don’t be dragged down by leanness of resources, staggering workload, sometimes-mundane nature of work or undervalued role by others</li>
</ul>
<p>18. The Importance of Pride</p>
<ul>
<li>No slouching</li>
<li>Do not accept a back seat</li>
<li>No sloppiness or mistakes should be tolerated; prompts the question &#8211; what else is wrong? How can I have confidence in anything?</li>
<li>It’s a huge job; don’t ever forget that</li>
<li>Keep the mission statement in mind</li>
<li>Cognizant of the overall framework that melds together strategic context and tactical execution</li>
</ul>
<p>19. Transferability to Other Risk-Related Areas</p>
<ul>
<li>Every single risk-related area could benefit by adhering to these 20 elements</li>
</ul>
<p>20. Risk Register</p>
<ul>
<li>Organizational (&#8220;tree&#8221;) view as well as workbench view</li>
<li>workbench for risk owners</li>
<li>doesn’t need to be exorbitant $</li>
<li>seemingly fashionable these days to downplay or disparage importance of the risk register</li>
<li><strong><a href="https://www.doublechecksoftware.com/products/risk/enterprise-risk-management-erm-one/">ERM One</a></strong> – a viable alternative to:
<ul>
<li>doing without an automated tool or</li>
<li>tolerating someone else’s system</li>
</ul>
</li>
</ul>
<p>Closing Thoughts:</p>
<ul>
<li>Get ready for the elevator speech</li>
<li>Trapped in the elevator with CEO and asked to give him/her your impressions of GRC/ERM priorities in 30 seconds</li>
<li>No excuses – take the time to do the dirty work beforehand</li>
<li>Connect the dots, dot by dot</li>
<li>Build the program, brick by brick</li>
<li>Bold, presumptuous goal (“World-Class”)?</li>
<li>Shoot for the moon; even if you miss, you’ll land among the stars</li>
<li>Common denominators</li>
<li>Better every day; better than yesterday</li>
<li>Incremental improvements</li>
<li>Keep attacking</li>
<li>Heed the children book classic &#8211; “Little Engine That Could”</li>
<li>Mission: reach the boys and girls on the other side of the mountain</li>
<li>When it found itself in trouble in trouble, neither a shiny new passenger engine, with all sorts of compartments, or a big strong engine was necessary</li>
<li>All that was needed was a little blue engine who “tugged and pulled”, “pulled and tugged”</li>
<li>“I think I can” was converted into “I thought I could”</li>
</ul>
<p>About the Author:<br />Michael Cawley is a risk management executive with a 35-year record of broad and diversified accomplishment in the strategic and tactical elements of corporate enterprise risk management (ERM). He performed day-to-day development and execution of a risk management program that covered all elements in the identification, assessment, mitigation and monitoring of all exposures within the corporate risk universe. Specific experience involved being a corporate risk manager for a service-related conglomerate (15 years) and then a biopharmaceutical manufacturer (10 years) before assuming an ERM governance and disclosure leadership role (10 years, through 2021) for a major worldwide financial entity. Currently, Mike serves as a Subject Matter Expert (SME) in an advisory role for ERM Best Practices for the advancement of DoubleCheck’s new ERM One<img src="https://s.w.org/images/core/emoji/15.0.3/72x72/2122.png" alt="™" class="wp-smiley" style="height: 1em; max-height: 1em;" /> application.</p>


<div class="wpforms-container wpforms-container-full" id="wpforms-116"><form id="wpforms-form-116" class="wpforms-validate wpforms-form" data-formid="116" method="post" enctype="multipart/form-data" action="/category/audit-management/feed/" data-token="d586098de15a2a4bd6cd724c5ceb7f9a" data-token-time="1785609587"><div class="wpforms-head-container"><div class="wpforms-title">Newsletter Signup</div><div class="wpforms-description">Interested in being informed when a new blog post is released?</div></div><noscript class="wpforms-error-noscript">Please enable JavaScript in your browser to complete this form.</noscript><div class="wpforms-field-container"><div id="wpforms-116-field_0-container" class="wpforms-field wpforms-field-name" data-field-id="0"><label class="wpforms-field-label" for="wpforms-116-field_0">Name <span class="wpforms-required-label">*</span></label><div class="wpforms-field-row wpforms-field-medium"><div class="wpforms-field-row-block wpforms-first wpforms-one-half"><input type="text" id="wpforms-116-field_0" class="wpforms-field-name-first wpforms-field-required" name="wpforms[fields][0][first]" required><label for="wpforms-116-field_0" class="wpforms-field-sublabel after">First</label></div><div class="wpforms-field-row-block wpforms-one-half"><input type="text" id="wpforms-116-field_0-last" class="wpforms-field-name-last wpforms-field-required" name="wpforms[fields][0][last]" required><label for="wpforms-116-field_0-last" class="wpforms-field-sublabel after">Last</label></div></div></div>		<div id="wpforms-116-field_4-container"
			class="wpforms-field wpforms-field-text"
			data-field-type="text"
			data-field-id="4"
			>
			<label class="wpforms-field-label" for="wpforms-116-field_4" >Email Title Company</label>
			<input type="text" id="wpforms-116-field_4" class="wpforms-field-medium" name="wpforms[fields][4]" >
		</div>
		<div id="wpforms-116-field_1-container" class="wpforms-field wpforms-field-email" data-field-id="1"><label class="wpforms-field-label" for="wpforms-116-field_1">Email <span class="wpforms-required-label">*</span></label><input type="email" id="wpforms-116-field_1" class="wpforms-field-medium wpforms-field-required" name="wpforms[fields][1]" spellcheck="false" required></div><div id="wpforms-116-field_2-container" class="wpforms-field wpforms-field-text" data-field-id="2"><label class="wpforms-field-label" for="wpforms-116-field_2">Company</label><input type="text" id="wpforms-116-field_2" class="wpforms-field-medium" name="wpforms[fields][2]" ></div><div id="wpforms-116-field_3-container" class="wpforms-field wpforms-field-text" data-field-id="3"><label class="wpforms-field-label" for="wpforms-116-field_3">Title</label><input type="text" id="wpforms-116-field_3" class="wpforms-field-medium" name="wpforms[fields][3]" ></div><script>
				( function() {
					const style = document.createElement( 'style' );

					style.appendChild( document.createTextNode( '#wpforms-116-field_4-container { position: absolute !important; overflow: hidden !important; display: inline !important; height: 1px !important; width: 1px !important; z-index: -1000 !important; padding: 0 !important; } #wpforms-116-field_4-container input { visibility: hidden; } #wpforms-conversational-form-page #wpforms-116-field_4-container label { counter-increment: none; }' ) );
					document.head.appendChild( style );
					document.currentScript?.remove();
				} )();
			</script></div><!-- .wpforms-field-container --><div class="wpforms-field wpforms-field-hp"><label for="wpforms-116-field-hp" class="wpforms-field-label">Message</label><input type="text" name="wpforms[hp]" id="wpforms-116-field-hp" class="wpforms-field-medium"></div><div class="wpforms-submit-container" ><input type="hidden" name="wpforms[id]" value="116"><input type="hidden" name="page_title" value="Audit Management"><input type="hidden" name="page_url" value="https://www.doublechecksoftware.com/category/audit-management/feed/"><button type="submit" name="wpforms[submit]" id="wpforms-submit-116" class="wpforms-submit" data-alt-text="Sending..." data-submit-text="Keep Me Informed" aria-live="assertive" value="wpforms-submit">Keep Me Informed</button></div></form></div>  <!-- .wpforms-container --><p>The post <a href="https://www.doublechecksoftware.com/why-settle-for-less-twenty-20-elements-in-a-world-class-erm-or-grc-program/">Why Settle For Less? Twenty (20) Elements in a World-Class ERM or GRC Program</a> first appeared on <a href="https://www.doublechecksoftware.com">DoubleCheck Software</a>.</p>]]></content:encoded>
					
					<wfw:commentRss>https://www.doublechecksoftware.com/why-settle-for-less-twenty-20-elements-in-a-world-class-erm-or-grc-program/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">3699</post-id>	</item>
		<item>
		<title>De-Mystifying (and Explaining the Connection Between) Risk-Related Acronyms and Phrases</title>
		<link>https://www.doublechecksoftware.com/de-mystifying-and-explaining-the-connection-between-risk-related-acronyms-and-phrases/</link>
					<comments>https://www.doublechecksoftware.com/de-mystifying-and-explaining-the-connection-between-risk-related-acronyms-and-phrases/#respond</comments>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Fri, 01 Sep 2023 13:07:25 +0000</pubDate>
				<category><![CDATA[Audit Management]]></category>
		<category><![CDATA[Cyber Security Risk Management]]></category>
		<category><![CDATA[Enterprise Risk Management]]></category>
		<category><![CDATA[GRC Implementation Success]]></category>
		<category><![CDATA[TPRM]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[cybersecurity software]]></category>
		<category><![CDATA[ERM]]></category>
		<category><![CDATA[erm software]]></category>
		<category><![CDATA[risk register]]></category>
		<category><![CDATA[Third Party Risk Management]]></category>
		<category><![CDATA[TPRM Software]]></category>
		<guid isPermaLink="false">https://www.doublechecksoftware.com/?p=3671</guid>

					<description><![CDATA[<p>One acronym after another. An ice cream headache, for sure, trying to understand the similarities, differences and connectivity between all these terms. You need to do it, however. Simplify, simplify, simplify. Break it down and truly comprehend everything. Get ready for the proverbial elevator speech, if the need for one materializes. Toward that goal, here<a href="https://www.doublechecksoftware.com/de-mystifying-and-explaining-the-connection-between-risk-related-acronyms-and-phrases/">[...]</a></p>
<p>The post <a href="https://www.doublechecksoftware.com/de-mystifying-and-explaining-the-connection-between-risk-related-acronyms-and-phrases/">De-Mystifying (and Explaining the Connection Between) Risk-Related Acronyms and Phrases</a> first appeared on <a href="https://www.doublechecksoftware.com">DoubleCheck Software</a>.</p>]]></description>
										<content:encoded><![CDATA[<p>One acronym after another.</p>
<p>An ice cream headache, for sure, trying to understand the similarities, differences and connectivity between all these terms.</p>
<p>You need to do it, however.</p>
<p>Simplify, simplify, simplify.</p>
<p>Break it down and truly comprehend everything.</p>
<p>Get ready for the proverbial elevator speech, if the need for one materializes.</p>
<p>Toward that goal, here are several recommendations:</p>
<ol>
<li><strong>Establish Enterprise Risk Management (ERM) as Your North Star</strong></li>
</ol>
<ul>
<li style="list-style-type: none;">
<ul>
<li>This is not meant to diminish or disparage other acronyms but merely to state an undeniable fact that needs to be accepted.</li>
<li>ERM is the granddaddy of them all.</li>
<li>Every component of all other risk-related acronyms or topics emanates from ERM or the framework established around ERM (Risk Management Framework).</li>
<li>In other words, the world revolves around ERM.</li>
<li>If you don’t like that fact, get over it.</li>
<li>Get on with the business of managing risk.</li>
</ul>
</li>
</ul>
<ol start="2">
<li><strong>Don’t: Quibble, Be Smarter by Half, or Get Hypothetical, Esoteric or Academic with your Language</strong></li>
</ol>
<ul>
<li style="list-style-type: none;">
<ul>
<li><span style="color: initial;">Every word matters.</span></li>
<li>Take no chances.</li>
<li>Leave nothing up in the air.</li>
<li>Use precision in all matters in such an important discipline.</li>
<li>Several useless debates, for example:</li>
</ul>
</li>
</ul>
<ol>
<li style="list-style-type: none;">
<ol>
<li style="list-style-type: none;">
<ol>
<li>Three Lines of Defense vs Three Lines of Responsibility. Use the former.</li>
<li>ERM vs Integrated Risk Management (IRM). Use the former.</li>
<li>ERM vs Strategic Risk Management. Use the former.</li>
</ol>
</li>
</ol>
</li>
</ol>
<ol start="3">
<li><strong>It’s All About the Risks, Stupid</strong></li>
</ol>
<ul>
<li style="list-style-type: none;">
<ul>
<li>I say this with affection, and as a reminder to myself, as much as to others.</li>
<li>Easy to lose sight of.</li>
<li>Treat risks as if you are bare-naked; do not rely on the safety blanket of insurance.</li>
<li>Remember: in the long-term, you will pay all your losses.</li>
<li>Another way of saying this: if a company had the financial wherewithal, it could (and should) self-insure all risks. No insurers, no brokers – just risk managers.</li>
<li>Imagine that.</li>
<li>GULP!<strong style="font-size: revert; color: initial;"> </strong></li>
</ul>
</li>
</ul>
<ol start="4">
<li><strong>The Risk Register</strong></li>
</ol>
<ul>
<li style="list-style-type: none;">
<ul>
<li>It can also be termed a Risk Universe; that’s OK</li>
<li>It’s not, however, a Risk Taxonomy (ouch, that sounds painful) or a Risk Catalog (when did we end up in the library?)</li>
<li>Call it Severity, not Impact, so that everyone in the organization is on the same page.</li>
<li>Define Severity in multiple ways, Using a 1-5 Rating Scale (e.g. Financial (% of Capital), Brand/Reputation, Regulatory Intervention, Strategic)</li>
<li>For the same reason, call it Likelihood, not Frequency.</li>
<li>Define Likelihood in a temporal manner, using a 1-5 Rating Scale (e.g. significant event happening every one, 5, 10, 25 and 50 years)</li>
<li>Bottom line: the fewer terms you use and the more rock solid certain those terms and definitions are, the better</li>
</ul>
</li>
</ul>
<ol start="5">
<li><strong>ERM vs GRC</strong></li>
</ol>
<ul>
<li style="list-style-type: none;">
<ul>
<li>GRC is a well-accepted, more bite-sized, subset of ERM, plain and simple.</li>
<li>The R (Risk) in both acronyms is identical – refers to ERM</li>
<li>The C in GRC is Compliance, an operational risk in the ERM risk register as well as one of the foundational components (Culture and Ethics) of ERM</li>
<li>Finally, G refers to both Corporate Governance, an ERM Operational risk, as well as to another ERM Foundational component, namely Governance. There, the various roles and responsibilities in the ERM equation are definitively laid out (e.g. Three Lines of Defense)</li>
</ul>
</li>
</ul>
<ol start="6">
<li><strong>ERM vs Compliance</strong></li>
</ol>
<ul>
<li style="list-style-type: none;">
<ul>
<li><span style="color: initial;">As stated above, the C refers to Compliance, an operational risk in the ERM risk register</span></li>
<li>There is nothing to prevent the Compliance function from deciding to further break down that exposure into sub-risks, in order to better delineate and manage on a more granular basis. (The last company I worked for broke down Compliance into 62 such sub-risks)</li>
</ul>
</li>
</ul>
<ol start="7">
<li><strong>ERM vs Internal Audit</strong></li>
</ol>
<ul>
<li style="list-style-type: none;">
<ul>
<li><span style="color: initial;">Internal Audit plays a vital 3</span><sup style="color: initial;">rd</sup><span style="color: initial;"> Line of Defense role in all risk matters</span></li>
<li>Audit Planning should align with risk priorities</li>
<li>Certain risks on the ERM risk register are more logically tied to Audit (e.g. Fraud); Head of Internal Audit could, in fact, be risk owner for those exposures</li>
</ul>
</li>
</ul>
<ol start="8">
<li><strong>ERM vs ESG</strong></li>
</ol>
<ul>
<li style="list-style-type: none;">
<ul>
<li><span style="color: initial;">The G (Governance) in ESG has already been covered, within ERM.</span></li>
<li>The S (Social) in ESG can be tracked to the ERM foundational component of Culture (Overall Cultural Model, Ethics and Compliance).</li>
<li>E, for Environmental, will align with the Climate Risk particulars enumerated on the ERM risk register.</li>
</ul>
</li>
</ul>
<ol start="9">
<li><strong>ERM vs DEI</strong></li>
</ol>
<ul>
<li style="list-style-type: none;">
<ul>
<li>There is not a more important risk related acronym on the horizon today than DEI (Diversity, Equity and Inclusiveness)</li>
<li>Start before you are ready on this – just get going.</li>
<li>If it needs improving, do so tomorrow from the base of today.</li>
<li>All of these items (DEI) need to be embedded in your Cultural Model, a vital ERM foundational component.</li>
<li>A crucial ERM risk like Human Resources – Management Development needs to be appropriately expanded and honed to yield the type of organization you want. How do you develop diverse talent, then grow and mentor them?</li>
<li>You need to operationalize DEI throughout the culture of the organization.</li>
<li>Set up key risk indicators (KRIs) in your ERM risk register to allow you to monitor – and constantly improve – your controls.</li>
<li>Like ERM, DEI is an iterative, evergreen process.</li>
</ul>
</li>
</ul>
<p>About the Author:<br />Michael Cawley is a risk management executive with a 35-year record of broad and diversified accomplishment in the strategic and tactical elements of corporate enterprise risk management (ERM). He performed day-to-day development and execution of a risk management program that covered all elements in the identification, assessment, mitigation and monitoring of all exposures within the corporate risk universe. Specific experience involved being a corporate risk manager for a service-related conglomerate (15 years) and then a biopharmaceutical manufacturer (10 years) before assuming an ERM governance and disclosure leadership role (10 years, through 2021) for a major worldwide financial entity. Currently, Mike serves as a Subject Matter Expert (SME) in an advisory role for ERM Best Practices for the advancement of DoubleCheck’s new ERM One<img src="https://s.w.org/images/core/emoji/15.0.3/72x72/2122.png" alt="™" class="wp-smiley" style="height: 1em; max-height: 1em;" /> application.</p>
<p> </p>


<div class="wpforms-container wpforms-container-full" id="wpforms-116"><form id="wpforms-form-116" class="wpforms-validate wpforms-form" data-formid="116" method="post" enctype="multipart/form-data" action="/category/audit-management/feed/" data-token="d586098de15a2a4bd6cd724c5ceb7f9a" data-token-time="1785609587"><div class="wpforms-head-container"><div class="wpforms-title">Newsletter Signup</div><div class="wpforms-description">Interested in being informed when a new blog post is released?</div></div><noscript class="wpforms-error-noscript">Please enable JavaScript in your browser to complete this form.</noscript><div class="wpforms-field-container"><div id="wpforms-116-field_0-container" class="wpforms-field wpforms-field-name" data-field-id="0"><label class="wpforms-field-label" for="wpforms-116-field_0">Name <span class="wpforms-required-label">*</span></label><div class="wpforms-field-row wpforms-field-medium"><div class="wpforms-field-row-block wpforms-first wpforms-one-half"><input type="text" id="wpforms-116-field_0" class="wpforms-field-name-first wpforms-field-required" name="wpforms[fields][0][first]" required><label for="wpforms-116-field_0" class="wpforms-field-sublabel after">First</label></div><div class="wpforms-field-row-block wpforms-one-half"><input type="text" id="wpforms-116-field_0-last" class="wpforms-field-name-last wpforms-field-required" name="wpforms[fields][0][last]" required><label for="wpforms-116-field_0-last" class="wpforms-field-sublabel after">Last</label></div></div></div>		<div id="wpforms-116-field_4-container"
			class="wpforms-field wpforms-field-text"
			data-field-type="text"
			data-field-id="4"
			>
			<label class="wpforms-field-label" for="wpforms-116-field_4" >Email Title Company</label>
			<input type="text" id="wpforms-116-field_4" class="wpforms-field-medium" name="wpforms[fields][4]" >
		</div>
		<div id="wpforms-116-field_1-container" class="wpforms-field wpforms-field-email" data-field-id="1"><label class="wpforms-field-label" for="wpforms-116-field_1">Email <span class="wpforms-required-label">*</span></label><input type="email" id="wpforms-116-field_1" class="wpforms-field-medium wpforms-field-required" name="wpforms[fields][1]" spellcheck="false" required></div><div id="wpforms-116-field_2-container" class="wpforms-field wpforms-field-text" data-field-id="2"><label class="wpforms-field-label" for="wpforms-116-field_2">Company</label><input type="text" id="wpforms-116-field_2" class="wpforms-field-medium" name="wpforms[fields][2]" ></div><div id="wpforms-116-field_3-container" class="wpforms-field wpforms-field-text" data-field-id="3"><label class="wpforms-field-label" for="wpforms-116-field_3">Title</label><input type="text" id="wpforms-116-field_3" class="wpforms-field-medium" name="wpforms[fields][3]" ></div><script>
				( function() {
					const style = document.createElement( 'style' );

					style.appendChild( document.createTextNode( '#wpforms-116-field_4-container { position: absolute !important; overflow: hidden !important; display: inline !important; height: 1px !important; width: 1px !important; z-index: -1000 !important; padding: 0 !important; } #wpforms-116-field_4-container input { visibility: hidden; } #wpforms-conversational-form-page #wpforms-116-field_4-container label { counter-increment: none; }' ) );
					document.head.appendChild( style );
					document.currentScript?.remove();
				} )();
			</script></div><!-- .wpforms-field-container --><div class="wpforms-field wpforms-field-hp"><label for="wpforms-116-field-hp" class="wpforms-field-label">Name</label><input type="text" name="wpforms[hp]" id="wpforms-116-field-hp" class="wpforms-field-medium"></div><div class="wpforms-submit-container" ><input type="hidden" name="wpforms[id]" value="116"><input type="hidden" name="page_title" value="Audit Management"><input type="hidden" name="page_url" value="https://www.doublechecksoftware.com/category/audit-management/feed/"><button type="submit" name="wpforms[submit]" id="wpforms-submit-116" class="wpforms-submit" data-alt-text="Sending..." data-submit-text="Keep Me Informed" aria-live="assertive" value="wpforms-submit">Keep Me Informed</button></div></form></div>  <!-- .wpforms-container -->



<p></p><p>The post <a href="https://www.doublechecksoftware.com/de-mystifying-and-explaining-the-connection-between-risk-related-acronyms-and-phrases/">De-Mystifying (and Explaining the Connection Between) Risk-Related Acronyms and Phrases</a> first appeared on <a href="https://www.doublechecksoftware.com">DoubleCheck Software</a>.</p>]]></content:encoded>
					
					<wfw:commentRss>https://www.doublechecksoftware.com/de-mystifying-and-explaining-the-connection-between-risk-related-acronyms-and-phrases/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">3671</post-id>	</item>
		<item>
		<title>Governance, Risk and Compliance (GRC) &#8211; Pursuing the “Ideal” Frame of Reference</title>
		<link>https://www.doublechecksoftware.com/governance-risk-and-compliance-grc-pursuing-the-ideal-frame-of-reference/</link>
					<comments>https://www.doublechecksoftware.com/governance-risk-and-compliance-grc-pursuing-the-ideal-frame-of-reference/#respond</comments>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Mon, 31 Jul 2023 18:21:16 +0000</pubDate>
				<category><![CDATA[Audit Management]]></category>
		<category><![CDATA[Enterprise Risk Management]]></category>
		<category><![CDATA[GRC Implementation Success]]></category>
		<category><![CDATA[TPRM]]></category>
		<category><![CDATA[ERM]]></category>
		<category><![CDATA[erm software]]></category>
		<category><![CDATA[GRC reports]]></category>
		<guid isPermaLink="false">https://www.doublechecksoftware.com/?p=3634</guid>

					<description><![CDATA[<p>When it comes to any discussion involving the acronym GRC (Governance, Risk and Compliance), understanding the speaker’s frame of reference is paramount. From a vendor’s perspective, GRC refers to an automated suite of capabilities designed to address a broad range of challenges associated with critical disciplines managed by the client (e.g. compliance, risk management, audit,<a href="https://www.doublechecksoftware.com/governance-risk-and-compliance-grc-pursuing-the-ideal-frame-of-reference/">[...]</a></p>
<p>The post <a href="https://www.doublechecksoftware.com/governance-risk-and-compliance-grc-pursuing-the-ideal-frame-of-reference/">Governance, Risk and Compliance (GRC) – Pursuing the “Ideal” Frame of Reference</a> first appeared on <a href="https://www.doublechecksoftware.com">DoubleCheck Software</a>.</p>]]></description>
										<content:encoded><![CDATA[<p>When it comes to any discussion involving the acronym GRC (Governance, Risk and Compliance), understanding the speaker’s frame of reference is paramount.</p>
<p>From a vendor’s perspective, GRC refers to an automated suite of capabilities designed to address a broad range of challenges associated with critical disciplines managed by the client (e.g. compliance, risk management, audit, corporate governance etc.), allowing that same company to reduce uncertainty, achieve the entity’s key strategic objectives and meet its stakeholder obligations.</p>
<p>Again, that perspective on GRC, which sounds straightforward enough, is being viewed through the eyes of the vendor.</p>
<p>Probably the same for every vendor, right?</p>
<p>Not so fast.</p>
<p>More holistically, would it be identical to how the client defines GRC?</p>
<p>Another no.</p>
<p>Let’s look at the delineating factors.</p>
<p>From a vendor perspective, what comprises each individual GRC system is totally dependent upon each vendor.</p>
<p>Simply put, not all systems are created with identical features.</p>
<p>The rationale is straightforward and understandable.</p>
<p>Look no further than the broad construct of the GRC umbrella – consisting of risk, compliance and a final element of governance that, drilling down to more specific risks, can be incredibly broad and wide-ranging (e.g. audit, corporate governance oversight, policy management, fraud, model, ESG, AI etc.).</p>
<p>It’s not hard to understand how the inevitable differences in system emphasis and packaging could (and do) result.</p>
<p>As a consequence, the GRC marketplace has found itself flooded with competing vendor-centric solutions, each seemingly in search of the next, new GRC challenge.</p>
<p>A skeptic could argue that each successive GRC solution becomes more inflexible, costly, complex and/or esoteric than the prior one.</p>
<p>With all these drivers, the “ask” of the GRC client often becomes to:</p>
<ul>
<li>Accept a system that is unwieldy and inflexible</li>
<li>Tolerate system features that you don’t need</li>
<li>Sacrifice other elements that you (or your Board of Directors) really want</li>
<li>Endure a bevy of reports, scorecards etc. that are neither pertinent nor understandable</li>
<li>Tolerate service standards that seem average, at best</li>
</ul>
<p>Needless to say, this is not really music to the client’s ears.</p>
<p>From a client’s perspective, therefore, the pursuit of a GRC solution all too often narrows to a choice that is best termed as “one-size-fits-all” or “take-it-or-leave-it”.</p>
<p>That’s not the way it’s supposed to be, if you roll back the tape and try to comprehend what GRC means, at the 40,000 foot level.  Maybe it’s time to take all this in and perform a sanity check of your GRC system.<br />After all, system capabilities and design should be all about the client.</p>
<p>With that in mind, how does a client think about GRC and, as a result, how should the vendor “ideally” design the system to meet those client needs?</p>
<p style="font-weight: 400;">First, the basic governing premise for GRC needs to be established, as follows:</p>
<p style="font-weight: 400;"><strong><em>The profound, pervasive and vitally important challenges that drive GRC emanate from the company, not from the vendor.</em></strong></p>
<p style="font-weight: 400;">This principle, which always has been, and always will be, true, cannot be overstated.</p>
<p>It’s not about forcing the client to perform contortions – and sacrifice functionality – to align with an inflexible, rigid tool.</p>
<p><em>As a 35-year real-life practitioner in the GRC space (25 years as a corporate risk manager and 10 years in the ERM Governance and Disclosure world), <strong>I know whereof I speak</strong>.</em></p>
<p>While the concept of GRC is said to have been created over 20 years ago (2002), the underlying challenges actually constituting those GRC exposures <strong>have been around forever</strong>.</p>
<p>They were certainly there in front of me on my first day as a risk manager in 1985, well before that “umbrella” concept of GRC was “created” and/or the first automated tool was developed.</p>
<p>Having said that, and mindful that there is no one “best” prescribed system or solution, it can be stated with certainty that a GRC automated tool should possess the following attributes:</p>
<ul>
<li>Capable of evolving and growing over time</li>
<li>Potential upgrades should be straightforward</li>
<li>Solution must be dynamic, nimble and agile</li>
<li>As such, it should be configurable</li>
<li>Can be either modular or holistic</li>
<li>Data must be able to be shared across modules</li>
<li>There needs to be cross-functional coordination</li>
<li>The system must be unified and linkable</li>
<li>There should be rich, robust functionality</li>
<li>The system needs to understand the business context of the company (what it does) as well as its culture and stakeholders</li>
<li>GRC strategy must be aligned with the overall business objectives</li>
<li>The tactical execution for each of the constituent parts of the GRC automated application must be part of the tool</li>
<li>Monitoring of GRC system performance must involve a robust, fully-embedded business intelligence platform</li>
</ul>
<p>With all these features in hand, a unified approach to GRC capabilities within the overall solution should allow a company to leverage GRC information across the enterprise.</p>
<p>By linking key elements across risk, compliance, audit and corporate governance (as well as related disciplines), the solution should be able to streamline processes and maximize utilization of information dashboard and analytics that cross boundaries.</p>
<p>Similarly, linked solutions reduce overlap, share overall insight, reuse work and tackle siloed GRC responses while securing what’s private.</p>
<p>A representative listing of GRC system activities might be, as follows:</p>
<p>Compliance</p>
<ul>
<li>Document controls, assess performance, manage exceptions</li>
<li>Tools to manage regulatory change and document compliance framework</li>
<li>Test or assess performance, manage remediation and share status results with stakeholders</li>
<li>Financial (SOX, PCI); Industry (NERC, HIPAA); Departmental (HR, IT)</li>
<li>Approvals, Attestations, and Certifications</li>
</ul>
<p>Risk</p>
<ul>
<li>Systematic approach to identify, assess, mitigate and monitor risks</li>
<li>Centers on risk register</li>
<li>Empower Risk Owners to manage and assess their own topic risk set</li>
<li>Goal is to collaborate with risk owners and other internal and external associates in a clear and transparent manner</li>
<li>Board-level reports and scorecards should be available to be generated in order to assess performance and establish risk priorities</li>
</ul>
<p>Audit</p>
<ul>
<li>Program definition based on client-specific reporting</li>
<li>Management insight into audit execution and planning</li>
<li>Management review, overrides to final plan</li>
<li>Engagement planning</li>
<li>Electronic workpaper management</li>
<li>Issue and remediation management</li>
</ul>
<p>Governance</p>
<ul>
<li>Policy definition</li>
<li>Policy review and renewal</li>
<li>Demonstrable performance</li>
</ul>
<p>Other GRC-Related Activities</p>
<ul>
<li>Model risk surveys, including reliance on Artificial Intelligence (AI)</li>
<li>Fraud-risk studies</li>
<li>Cyber risk (information security)</li>
</ul>
<p>Summary</p>
<p>An “ideal” GRC solution revolves around specific customer needs. Enterprise GRC software that supports Compliance, Risk, Audit or Governance needs should be highly configurable solutions that can be tailored to a company’s users, data and processes. Embedded Business intelligence features should generate dashboards and reports that are needed for internal and external purposes. GRC Solutions should support business processes, not the other way around. Each of the components of GRC are integrally linked to the achievement of a company’s corporate objectives.</p>
<p>About the Author:<br />Michael Cawley is a risk management executive with a 35-year record of broad and diversified accomplishment in the strategic and tactical elements of corporate enterprise risk management (ERM). He performed day-to-day development and execution of a risk management program that covered all elements in the identification, assessment, mitigation and monitoring of all exposures within the corporate risk universe. Specific experience involved being a corporate risk manager for a service-related conglomerate (15 years) and then a biopharmaceutical manufacturer (10 years) before assuming an ERM governance and disclosure leadership role (10 years, through 2021) for a major worldwide financial entity. Currently, Mike serves as a Subject Matter Expert (SME) in an advisory role for ERM Best Practices for the advancement of DoubleCheck’s new ERM One<img src="https://s.w.org/images/core/emoji/15.0.3/72x72/2122.png" alt="™" class="wp-smiley" style="height: 1em; max-height: 1em;" /> application.</p>


<div class="wpforms-container wpforms-container-full" id="wpforms-116"><form id="wpforms-form-116" class="wpforms-validate wpforms-form" data-formid="116" method="post" enctype="multipart/form-data" action="/category/audit-management/feed/" data-token="d586098de15a2a4bd6cd724c5ceb7f9a" data-token-time="1785609587"><div class="wpforms-head-container"><div class="wpforms-title">Newsletter Signup</div><div class="wpforms-description">Interested in being informed when a new blog post is released?</div></div><noscript class="wpforms-error-noscript">Please enable JavaScript in your browser to complete this form.</noscript><div class="wpforms-field-container"><div id="wpforms-116-field_0-container" class="wpforms-field wpforms-field-name" data-field-id="0"><label class="wpforms-field-label" for="wpforms-116-field_0">Name <span class="wpforms-required-label">*</span></label><div class="wpforms-field-row wpforms-field-medium"><div class="wpforms-field-row-block wpforms-first wpforms-one-half"><input type="text" id="wpforms-116-field_0" class="wpforms-field-name-first wpforms-field-required" name="wpforms[fields][0][first]" required><label for="wpforms-116-field_0" class="wpforms-field-sublabel after">First</label></div><div class="wpforms-field-row-block wpforms-one-half"><input type="text" id="wpforms-116-field_0-last" class="wpforms-field-name-last wpforms-field-required" name="wpforms[fields][0][last]" required><label for="wpforms-116-field_0-last" class="wpforms-field-sublabel after">Last</label></div></div></div><div id="wpforms-116-field_1-container" class="wpforms-field wpforms-field-email" data-field-id="1"><label class="wpforms-field-label" for="wpforms-116-field_1">Email <span class="wpforms-required-label">*</span></label><input type="email" id="wpforms-116-field_1" class="wpforms-field-medium wpforms-field-required" name="wpforms[fields][1]" spellcheck="false" required></div>		<div id="wpforms-116-field_4-container"
			class="wpforms-field wpforms-field-text"
			data-field-type="text"
			data-field-id="4"
			>
			<label class="wpforms-field-label" for="wpforms-116-field_4" >Company Name Title</label>
			<input type="text" id="wpforms-116-field_4" class="wpforms-field-medium" name="wpforms[fields][4]" >
		</div>
		<div id="wpforms-116-field_2-container" class="wpforms-field wpforms-field-text" data-field-id="2"><label class="wpforms-field-label" for="wpforms-116-field_2">Company</label><input type="text" id="wpforms-116-field_2" class="wpforms-field-medium" name="wpforms[fields][2]" ></div><div id="wpforms-116-field_3-container" class="wpforms-field wpforms-field-text" data-field-id="3"><label class="wpforms-field-label" for="wpforms-116-field_3">Title</label><input type="text" id="wpforms-116-field_3" class="wpforms-field-medium" name="wpforms[fields][3]" ></div><script>
				( function() {
					const style = document.createElement( 'style' );

					style.appendChild( document.createTextNode( '#wpforms-116-field_4-container { position: absolute !important; overflow: hidden !important; display: inline !important; height: 1px !important; width: 1px !important; z-index: -1000 !important; padding: 0 !important; } #wpforms-116-field_4-container input { visibility: hidden; } #wpforms-conversational-form-page #wpforms-116-field_4-container label { counter-increment: none; }' ) );
					document.head.appendChild( style );
					document.currentScript?.remove();
				} )();
			</script></div><!-- .wpforms-field-container --><div class="wpforms-field wpforms-field-hp"><label for="wpforms-116-field-hp" class="wpforms-field-label">Website</label><input type="text" name="wpforms[hp]" id="wpforms-116-field-hp" class="wpforms-field-medium"></div><div class="wpforms-submit-container" ><input type="hidden" name="wpforms[id]" value="116"><input type="hidden" name="page_title" value="Audit Management"><input type="hidden" name="page_url" value="https://www.doublechecksoftware.com/category/audit-management/feed/"><button type="submit" name="wpforms[submit]" id="wpforms-submit-116" class="wpforms-submit" data-alt-text="Sending..." data-submit-text="Keep Me Informed" aria-live="assertive" value="wpforms-submit">Keep Me Informed</button></div></form></div>  <!-- .wpforms-container --><p>The post <a href="https://www.doublechecksoftware.com/governance-risk-and-compliance-grc-pursuing-the-ideal-frame-of-reference/">Governance, Risk and Compliance (GRC) – Pursuing the “Ideal” Frame of Reference</a> first appeared on <a href="https://www.doublechecksoftware.com">DoubleCheck Software</a>.</p>]]></content:encoded>
					
					<wfw:commentRss>https://www.doublechecksoftware.com/governance-risk-and-compliance-grc-pursuing-the-ideal-frame-of-reference/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">3634</post-id>	</item>
		<item>
		<title>Harvesting Information From GRC Data—The Promise of Business Intelligence Tools</title>
		<link>https://www.doublechecksoftware.com/harvesting-information-from-grc-data-the-promise-of-business-intelligence-tools/</link>
					<comments>https://www.doublechecksoftware.com/harvesting-information-from-grc-data-the-promise-of-business-intelligence-tools/#respond</comments>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Tue, 01 Mar 2022 15:05:44 +0000</pubDate>
				<category><![CDATA[Audit Management]]></category>
		<category><![CDATA[Cyber Security Risk Management]]></category>
		<category><![CDATA[Enterprise Risk Management]]></category>
		<category><![CDATA[GRC Implementation Success]]></category>
		<category><![CDATA[TPRM]]></category>
		<category><![CDATA[embedded business intelligence]]></category>
		<category><![CDATA[GRC reports]]></category>
		<category><![CDATA[TPRM Software]]></category>
		<guid isPermaLink="false">https://www.doublechecksoftware.com/?p=2794</guid>

					<description><![CDATA[<p>Thirty-five years ago, my first article was published in a professional journal. It was the outgrowth of a talk I gave at a business conference on the use of computer generated graphical information reporting. In 1987 those technologies were in their infancy. Computerized business graphics, pie, line, and bar charts, generated using desktop systems and<a href="https://www.doublechecksoftware.com/harvesting-information-from-grc-data-the-promise-of-business-intelligence-tools/">[...]</a></p>
<p>The post <a href="https://www.doublechecksoftware.com/harvesting-information-from-grc-data-the-promise-of-business-intelligence-tools/">Harvesting Information From GRC Data—The Promise of Business Intelligence Tools</a> first appeared on <a href="https://www.doublechecksoftware.com">DoubleCheck Software</a>.</p>]]></description>
										<content:encoded><![CDATA[<p>Thirty-five years ago, my first article was published in a professional journal. It was the outgrowth of a talk I gave at a business conference on the use of computer generated graphical information reporting. In 1987 those technologies were in their infancy. Computerized business graphics, pie, line, and bar charts, generated using desktop systems and output to paper, overheads, or slides were a big deal then. More sophisticated Gantt, Pert, and process flow charts sometimes required the power of mini computers and dedicated graphic terminals to produce reasonably professional looking results, for their time.</p>
<p>Today’s tools are dramatically more powerful, as are the portable systems on which they run. Beyond power, the diversity of data manipulation tools, visual display options, formats, presentation options of color, perspective, and style all capable of publication and distribution through multiple electronic means create limitless opportunity to create and present compelling representations of structured and unstructured data to managers and executives eager for reports on performance, profit, customer preferences, brand value, opportunity, and risk. And that brings us to a significant problem facing contemporary business leadership in the 21st century.</p>
<p>A triad of questions defines the problem:</p>
<p><strong><em>“Do you know what you need to know to effectively run your business?”</em></strong></p>
<p>coupled with</p>
<p><strong><em>“As a result of knowing _____, what action would you take?”</em></strong></p>
<p>The third question is one rarely asked by senior leadership, in my experience…</p>
<p><strong><em>“If you had answers to the first two questions, would your management team know what to do with the information?”</em></strong></p>
<p><span style="color: #3366ff;"><strong>A Data Feast Amidst Information Hunger</strong></span><br />We have plenty of facts and details about all sorts of macro and micro measures. The proliferation and transformation of business processes into digital methods has given rise to volumes of raw data businesses in the late 20th century could only dream of capturing, storing, and exploring. Risk data was far more subjective, unstructured and lacked the precision available today. The same was generally true for many other data categories covering operating, financial, customer, partner, regulatory and compliance data. Facts alone are often incomplete communicators. And while associations possible through data manipulation tools may be novel and “interesting”, they may not be actionable. For example, relating new customer location data with lunar phase data might create something interesting. But, “As a result of knowing this what action would you take?” We cannot manage the phase of the moon. Also, data presented in charts and graphs doesn’t always tell you something useful. Let’s look at a very simple instance and see how a small alteration can lead data down the road toward useful information.</p>
<p>Here’s a simple bar chart in figure 1: By itself it really doesn’t provide<img decoding="async" class="size-medium wp-image-2806 alignleft" src="https://www.doublechecksoftware.com/wp-content/uploads/2022/02/Figures-1-2-3-159x300.png" alt="" width="159" height="300" srcset="https://www.doublechecksoftware.com/wp-content/uploads/2022/02/Figures-1-2-3-159x300.png 159w, https://www.doublechecksoftware.com/wp-content/uploads/2022/02/Figures-1-2-3-544x1024.png 544w, https://www.doublechecksoftware.com/wp-content/uploads/2022/02/Figures-1-2-3-80x150.png 80w, https://www.doublechecksoftware.com/wp-content/uploads/2022/02/Figures-1-2-3.png 624w" sizes="(max-width: 159px) 100vw, 159px" /> much more than a representation of a distribution of values. Perhaps that’s useful, but the measure of actionable information is nearly zero. Now, let’s add a “goal line” to Figures 2 and 3, where values above the line represent clear success and those below opportunities and challenges that should be explored and addressed. Your results, areas for attention and likely next steps vary greatly even between figure 2 and 3. These are very simplistic examples. Today’s graphical arrays are visually more sophisticated, and analytically often more complicated. The point is, the tool alone is not where the “intelligence” is expressed in Business Intelligence software. The intelligence comes from the interpretation and useful combination of data, which requires prerequisite understanding of what the data is, where it came from, how it was created, and when. While these examples are oversimplified, figures 2 &amp; 3 begin to offer some useful and actionable information by pointing out performance against a standard of expectation, leading to follow-up on what is working well, and what is not, and what performance drivers may be adjusted to help marginal performance cases improve. Those answers may lead to changes in a variety of operating, policy, or process directions to correct performance concerns.</p>
<p>This is an example about one very simple metric, using a very simple graphical representation. Today’s business intelligence (BI) tools can do much more with much more complicated data. If you tracked every possible metric you could measure, and presented results this way, you’d overwhelm even the most knowledgeable stakeholder or leader. Knowing and applying context and conditional relationships helps narrow focus, support drill down detail where beneficial, and bring the real power of business intelligence tools to bear.</p>
<p><strong><span style="color: #3366ff;">What Do You Need To Know?</span></strong><br />The oft cited, but very wrong answer is “everything”! It’s just not functional. And you’d be buried in data points that told you nothing useful. Do you drive a car? Examine your dashboard. Where is the indicator for each cylinders’ compression ratio? Where is your brake pad temperature monitor? What?! You don’t know the precise volume of fuel remaining in milliliters and ounces? How are you possibly functioning? But you are. You have all the key performance and status indicators needed to operate and direct your car safely to your intended destination. You have transportation. If there was a problem, and your mechanic were to seek out some of these answers as part of a diagnostic exercise, that more concise and focused context brings in the need for different, and more specific detail. You need to know when something is and isn’t working as intended and designed. When you learn of a problem, you need to inform your specialists with the information needed to diagnose the root cause, proscribe solutions, and test remediated functions. Go back to the questions at the start of this article, to test the utility of the metrics you wish to gather. See how many pass successfully through no.’s 2 &amp; 3. Start with that subset.</p>
<p>You also need to know the key driving chains that influence the metrics you do monitor. This is a kind of technical perspective upon context. For each of your key performance indicators (KPI’s) and key risk indicators (KRI’s) you need to map out what business processes influence those measures, where the source data is gathered that is used to calculate each indicator, how often, where it’s stored, and how it’s validated. This is vital context, that can provide actionable direction should an indicator’s value suddenly shift from expected norms.</p>
<p><span style="color: #3366ff;"><strong>So, Where Does BI Fit?</strong></span><br />Business Intelligence software is a tool. And, like any other tool, its value is in the thoughtful, careful application by its handler. BI software is really good at helping you explore data relationships. It works best when applied in conjunction with your own knowledge of how your business works. Often the relationships between data values and different metrics may be obvious, and some may offer new insights to how seemingly unrelated processes impact one another. Use these features to explore these unique key driving chains. They may reveal important metrics to incorporate onto your standard “dashboard” of key operating metrics.</p>
<p>There’s an implicit benefit here that may not be obvious. Data silos, created by and supporting of dedicated systems for a specific discipline or purpose may be present across your enterprise. One of the key features of a BI tool is its ability to aggregate, interpret, and represent data from a consolidated variety of sources. This is significant. Without this capability the potential to identify useful key driving chains, letting you identify and represent the most insightful KRI’s and KPI’s would be seriously hampered. Embedding BI functionality within a platform that can collect and store data from a variety of disciplines or functions, such as an Enterprise Resource Planning (ERP) or an enterprise Integrated Risk Management (IRM) solution can deliver significant value through its ability to provide a single, authoritative resource for decision data. Value is created in part through streamlined processes, enhanced efficiency, and simplified system management. Additionally, the ability to manage access, protect confidential data, provide vetted information, and efficiently publish business information through a consistent, reliable portal cannot be overestimated.</p>
<p>BI tools can offer insight into how clients and customers engage your business, help inventory managers fine tune reorder horizons to minimize overstocks and stock-outs, and inform you of sales trends, client preferences, and campaign reactions far sooner than training periodical reporting. Having data and BI tools proximate helps polish efficiency in getting actionable information into managers and leaderships’ hands sooner, so that your business runs with clear vision of the road before you.</p>
<p><strong><span style="color: #3366ff;">Visual Tools, Actionable Information</span></strong><br />Visual representation of data is a valuable characteristic of BI tools. We are a visual society. While there are some of us who relate best to columns and arrays of numbers or symbols, for the most part people relate to visual representations of data. Pictures over words. It’s a very powerful method for effectively communicating fact, concept, and relationships. Pictures often traverse the boundaries and nuances of words and speech. Pictograms and charts form an almost universal language of their own. Whether you are working with simple heat maps representing significant risk areas, or double axis charts depicting client attributes and revenues, or more complex and sophisticated arrays, data visualization helps you highlight and pinpoint key messages and information. They are able to take large amounts of relatively complex data and create images that simplify and communicate actionable information messages your leadership can employ to manage your business, and maximize its potential to achieve stated goals. Great visualizations are clear pictures of declarative statements. <img decoding="async" class=" wp-image-2808 alignleft" src="https://www.doublechecksoftware.com/wp-content/uploads/2022/02/Figure-4-300x294.png" alt="" width="176" height="172" srcset="https://www.doublechecksoftware.com/wp-content/uploads/2022/02/Figure-4-300x294.png 300w, https://www.doublechecksoftware.com/wp-content/uploads/2022/02/Figure-4-150x147.png 150w, https://www.doublechecksoftware.com/wp-content/uploads/2022/02/Figure-4.png 624w" sizes="(max-width: 176px) 100vw, 176px" />As a best practice, I recommend visuals be titled by a declarative remark stating exactly what the visual is illustrating. Figure 4 reuses our example from earlier in this article, but  note the clarity the title now adds to the image from figure 3. There can be no doubt about the message, and it immediately leads to a discussion of what’s work so well so often, and why not in the one location with disappointing results. More sophisticated visuals can convey other relationships, changes over time, year over year comparisons, the driving chain influences implicit in your KP/RI’s and more.</p>
<p><strong><span style="color: #3366ff;">BI Tools and Your GRC</span></strong><br />Your GRC is an integration platform that can host data about many different risk categories, including operational, financial, third party and cyber to name a few. It’s also a place where regulatory and contractual obligations, compliance, and audit processes may be managed, remediation specified, tracked and reported. This single point repository for overall governance, risk, and compliance is a great place to house BI tools to explore the consolidated data, across these disciplines and actions, to help you identify, explore, analyze, and communicate current performance, key relationships, and potential opportunities to protect and enhance your overall performance. BI tools help you realize and maximize the value inherit within your consolidated data. Product and service performance, both current and predictive are within its grasp. Likewise, critical risks, vulnerabilities and opportunities for leveraged remediation become clear. Potential third party issues, whether supply chain related, or implicit in vulnerabilities they impose on your infrastructure become visible. And so much more.</p>
<p>The investment in a GRC tool is enhanced and brought to maximum value in large part through the business questions it answers, the proactive vision it affords, and the informative support it provides leadership. Your BI tools are the glasses that clarify this world and sharpen your vision of your current state, with enhanced acuity to look towards the horizon and anticipate tomorrow.</p>
<p>About the Author:<br />Simon Goldstein is an accomplished senior executive blending both technology and business expertise to formulate, impact, and achieve corporate strategies. A retired senior manager of Accenture’s IT Security and Risk Management practice, he has achieved results through the creation of customer value, business growth, and collaboration. An experienced change agent with primary experience in financial, technology, and retail industries, he’s led efforts to achieve ISO2700x certification and HIPAA compliance, as well as held credentials of CRISC, CISM, CISA.</p>
<p>&#8212;</p>
<p><span style="color: #3366ff;">Some observations from DoubleCheck Software on Business Intelligence tools :</span></p>
<p>It is critical to have flexibility and simple tools for extracting BI data from your GRC system into comprehensive, visually informative documents and slideware. Reports 1 &amp; 2 below demonstrate different ways to render information to Management, Board of Directors, and team members. Report 1 (Risk Dashboard) provides a snapshot of the entire Risk Register, including overall Risk Status, Risk Distribution via a Heat Map with drillable values, Risk Distribution over Time, and monetary Risk Impact over Time. Report 2 (Enterprise Risks) goes deeper and provides more specific Risk Details.</p>
<p>Report 1</p>
<p><img fetchpriority="high" decoding="async" class="alignnone  wp-image-2801" src="https://www.doublechecksoftware.com/wp-content/uploads/2022/02/Risk-Dashboard-300x199.png" alt="" width="573" height="380" srcset="https://www.doublechecksoftware.com/wp-content/uploads/2022/02/Risk-Dashboard-300x199.png 300w, https://www.doublechecksoftware.com/wp-content/uploads/2022/02/Risk-Dashboard-1024x678.png 1024w, https://www.doublechecksoftware.com/wp-content/uploads/2022/02/Risk-Dashboard-150x99.png 150w, https://www.doublechecksoftware.com/wp-content/uploads/2022/02/Risk-Dashboard-768x509.png 768w, https://www.doublechecksoftware.com/wp-content/uploads/2022/02/Risk-Dashboard-1536x1018.png 1536w, https://www.doublechecksoftware.com/wp-content/uploads/2022/02/Risk-Dashboard-2048x1357.png 2048w" sizes="(max-width: 573px) 100vw, 573px" /></p>
<p>Report 2</p>
<p><img loading="lazy" decoding="async" class="alignnone  wp-image-2802" src="https://www.doublechecksoftware.com/wp-content/uploads/2022/02/Risk-Heatmap-v2-300x206.png" alt="" width="572" height="393" srcset="https://www.doublechecksoftware.com/wp-content/uploads/2022/02/Risk-Heatmap-v2-300x206.png 300w, https://www.doublechecksoftware.com/wp-content/uploads/2022/02/Risk-Heatmap-v2-1024x703.png 1024w, https://www.doublechecksoftware.com/wp-content/uploads/2022/02/Risk-Heatmap-v2-150x103.png 150w, https://www.doublechecksoftware.com/wp-content/uploads/2022/02/Risk-Heatmap-v2-768x528.png 768w, https://www.doublechecksoftware.com/wp-content/uploads/2022/02/Risk-Heatmap-v2-1536x1055.png 1536w, https://www.doublechecksoftware.com/wp-content/uploads/2022/02/Risk-Heatmap-v2-2048x1407.png 2048w" sizes="(max-width: 572px) 100vw, 572px" /></p>
<p> </p>


<div class="wpforms-container wpforms-container-full" id="wpforms-116"><form id="wpforms-form-116" class="wpforms-validate wpforms-form" data-formid="116" method="post" enctype="multipart/form-data" action="/category/audit-management/feed/" data-token="d586098de15a2a4bd6cd724c5ceb7f9a" data-token-time="1785609587"><div class="wpforms-head-container"><div class="wpforms-title">Newsletter Signup</div><div class="wpforms-description">Interested in being informed when a new blog post is released?</div></div><noscript class="wpforms-error-noscript">Please enable JavaScript in your browser to complete this form.</noscript><div class="wpforms-field-container"><div id="wpforms-116-field_0-container" class="wpforms-field wpforms-field-name" data-field-id="0"><label class="wpforms-field-label" for="wpforms-116-field_0">Name <span class="wpforms-required-label">*</span></label><div class="wpforms-field-row wpforms-field-medium"><div class="wpforms-field-row-block wpforms-first wpforms-one-half"><input type="text" id="wpforms-116-field_0" class="wpforms-field-name-first wpforms-field-required" name="wpforms[fields][0][first]" required><label for="wpforms-116-field_0" class="wpforms-field-sublabel after">First</label></div><div class="wpforms-field-row-block wpforms-one-half"><input type="text" id="wpforms-116-field_0-last" class="wpforms-field-name-last wpforms-field-required" name="wpforms[fields][0][last]" required><label for="wpforms-116-field_0-last" class="wpforms-field-sublabel after">Last</label></div></div></div><div id="wpforms-116-field_1-container" class="wpforms-field wpforms-field-email" data-field-id="1"><label class="wpforms-field-label" for="wpforms-116-field_1">Email <span class="wpforms-required-label">*</span></label><input type="email" id="wpforms-116-field_1" class="wpforms-field-medium wpforms-field-required" name="wpforms[fields][1]" spellcheck="false" required></div>		<div id="wpforms-116-field_4-container"
			class="wpforms-field wpforms-field-text"
			data-field-type="text"
			data-field-id="4"
			>
			<label class="wpforms-field-label" for="wpforms-116-field_4" >Name Company Title</label>
			<input type="text" id="wpforms-116-field_4" class="wpforms-field-medium" name="wpforms[fields][4]" >
		</div>
		<div id="wpforms-116-field_2-container" class="wpforms-field wpforms-field-text" data-field-id="2"><label class="wpforms-field-label" for="wpforms-116-field_2">Company</label><input type="text" id="wpforms-116-field_2" class="wpforms-field-medium" name="wpforms[fields][2]" ></div><div id="wpforms-116-field_3-container" class="wpforms-field wpforms-field-text" data-field-id="3"><label class="wpforms-field-label" for="wpforms-116-field_3">Title</label><input type="text" id="wpforms-116-field_3" class="wpforms-field-medium" name="wpforms[fields][3]" ></div><script>
				( function() {
					const style = document.createElement( 'style' );

					style.appendChild( document.createTextNode( '#wpforms-116-field_4-container { position: absolute !important; overflow: hidden !important; display: inline !important; height: 1px !important; width: 1px !important; z-index: -1000 !important; padding: 0 !important; } #wpforms-116-field_4-container input { visibility: hidden; } #wpforms-conversational-form-page #wpforms-116-field_4-container label { counter-increment: none; }' ) );
					document.head.appendChild( style );
					document.currentScript?.remove();
				} )();
			</script></div><!-- .wpforms-field-container --><div class="wpforms-field wpforms-field-hp"><label for="wpforms-116-field-hp" class="wpforms-field-label">Comment</label><input type="text" name="wpforms[hp]" id="wpforms-116-field-hp" class="wpforms-field-medium"></div><div class="wpforms-submit-container" ><input type="hidden" name="wpforms[id]" value="116"><input type="hidden" name="page_title" value="Audit Management"><input type="hidden" name="page_url" value="https://www.doublechecksoftware.com/category/audit-management/feed/"><button type="submit" name="wpforms[submit]" id="wpforms-submit-116" class="wpforms-submit" data-alt-text="Sending..." data-submit-text="Keep Me Informed" aria-live="assertive" value="wpforms-submit">Keep Me Informed</button></div></form></div>  <!-- .wpforms-container --><p>The post <a href="https://www.doublechecksoftware.com/harvesting-information-from-grc-data-the-promise-of-business-intelligence-tools/">Harvesting Information From GRC Data—The Promise of Business Intelligence Tools</a> first appeared on <a href="https://www.doublechecksoftware.com">DoubleCheck Software</a>.</p>]]></content:encoded>
					
					<wfw:commentRss>https://www.doublechecksoftware.com/harvesting-information-from-grc-data-the-promise-of-business-intelligence-tools/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2794</post-id>	</item>
		<item>
		<title>When Comes December; Tailoring Your GRC Programs For The Coming Year</title>
		<link>https://www.doublechecksoftware.com/when-comes-december-tailoring-your-grc-programs-for-the-coming-year/</link>
					<comments>https://www.doublechecksoftware.com/when-comes-december-tailoring-your-grc-programs-for-the-coming-year/#respond</comments>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Wed, 01 Dec 2021 14:52:36 +0000</pubDate>
				<category><![CDATA[Audit Management]]></category>
		<category><![CDATA[Cyber Security Risk Management]]></category>
		<category><![CDATA[Enterprise Risk Management]]></category>
		<category><![CDATA[GRC Implementation Success]]></category>
		<category><![CDATA[TPRM]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[cybersecurity software]]></category>
		<category><![CDATA[ERM]]></category>
		<category><![CDATA[TPRM Software]]></category>
		<guid isPermaLink="false">https://www.doublechecksoftware.com/?p=2750</guid>

					<description><![CDATA[<p>December brings more to our days than images of bright lights, holiday cheer, family gatherings, and for some, maybe a sprinkling of snow. In our work-realm of business and cyber risk management, it’s a time for reflection, refinement, and preparation for the year to come. Unless your business is retail or related, and you’re panting<a href="https://www.doublechecksoftware.com/when-comes-december-tailoring-your-grc-programs-for-the-coming-year/">[...]</a></p>
<p>The post <a href="https://www.doublechecksoftware.com/when-comes-december-tailoring-your-grc-programs-for-the-coming-year/">When Comes December; Tailoring Your GRC Programs For The Coming Year</a> first appeared on <a href="https://www.doublechecksoftware.com">DoubleCheck Software</a>.</p>]]></description>
										<content:encoded><![CDATA[<p>December brings more to our days than images of bright lights, holiday cheer, family gatherings, and for some, maybe a sprinkling of snow. In our work-realm of business and cyber risk management, it’s a time for reflection, refinement, and preparation for the year to come. Unless your business is retail or related, and you’re panting your way to the gift giving finish line, this is a great time to look back for a moment and answer some questions about your cyber risk management program, and your risk processes overall. For example:</p>
<ul>
<li>What has worked quite well in the past year?</li>
<li>What has not, and why?</li>
<li>What unique challenges do you anticipate for 2022?</li>
<li>Are there processes that bear attention and refinements</li>
<li>Are there gaps in what you do that should be addressed?</li>
<li>Are you aligned to your firm’s business goals and strategy for 2022?</li>
</ul>
<p>It can be useful to get some input from your stakeholders and key users. Their perceptions, insights, and priorities may offer other perspectives for you to consider. The information you provide to inform decisions and direct actions only realizes its full value if it’s readily available and comprehensible for them. Also include your support resources, in IT, staff education, contributing departments, and management. And if there’re gaps in the program from their perspectives, it’ll be made clear from their feedback. Just including your primary audiences in your review process incorporates them into shared program ownership, which is important of itself.</p>
<p><span style="color: #3366ff;"><strong>Features and Processes</strong></span><br>
Improving your GRC program’s usefulness requires consideration of both. Basically, what and how, and also when. Tailoring here is not so different than tailoring of good clothing (confession: I’m the grandson of a master tailor). You examine fit, identify areas that need alteration, determine what that adjustment needs to be, examine the resources available to employ, decide what you can do to create the best “fit” result, size and mark your adjustments, and execute from there. The first two steps are accomplished through review and feedback. Those help you identify which changes would refine your program to a more perfect “fit” for your business.</p>
<p>Next, consider what’s missing or imperfect. The content here generally falls into two categories, features and processes. For your GRC, features would likely include modules you might want to add, like third party risk management (TPRM), (or activate if you’ve not yet made use of them), or interfaces to other data, internal or external, extended security provisions, even changes to labels and language to reflect norms and culture within your firm. Processes may relate to risk assessment methods, workflows, communications, training practices, even alterations to authentication and permission granting.</p>
<p><span style="color: #3366ff;"><strong>Features</strong></span><br>
Answer these simple questions: “what do we need to know that we cannot today?”, and “How can we get that information?”. Armed with those answers you can evaluate whether you need to adjust a configuration or setting in what you already use, need to integrate a data source that already exists somewhere else within your infrastructure, or in fact, you need to acquire something that will enable you to do what you cannot. This is not just a cost saving exercise. It’s also a design and maintenance management practice to keep your infrastructure as straightforward and contained as possible. Security plays a role here too. Internal data feeds are easier to validate, manage, and secure. Configuration management is a more straightforward approach too, helping to assure your software maintenance path remains relatively linear. Adding modules to your GRC is also a great way to extend functionality, when it’s represented through features designed for that specific purpose. Modules likely will open doors for opportunity to do more than you may need at this moment, but present greater flexibility and resources to continue to refine and extend your capabilities as they continue to evolve. They are also a “hedge” against any perceived desire to insert custom code into your platform as a way to get that information or perform a required process.</p>
<p>I’ve often spoken out against custom code unless your vendor commits to incorporating and supporting it in subsequent releases. (This is sometimes called an advanced feature by some). Many of the biggest maintenance and performance issues I’ve seen have their root cause in some piece of unsupported custom code interfering with a future product release. It’s something to avoid if at all possible. Instead, explore your available configuration settings and work with your vendor to seek a supportable solution. Also keep in mind that custom code is not always the same as customization. Many vendors offer you options (configuration capabilities) and allow you to create custom fields, and to rename existing fields to use language and conventions consistent within your own company’s and industry’s culture. All those changes are consistent with the “no custom code” approach mentioned above. Also, when you do change field names, look for functions that support global changes, so you maintain consistency across panels, modules, and processes. That will keep user training much easier and adoption more rapid.</p>
<p><strong><span style="color: #3366ff;">Processes</span></strong><br>
Often times, for control or regulatory purposes, or just to further tailor a system to do things “your way,” how you get somewhere is of equal importance to arriving where you were headed. One obvious place to start is with workflow configurations. Have you identified any process bottlenecks from your risk assessments, vendor assessments or onboarding processes (if you have some TPRM functions incorporated within your platform), or compliance management? If so this is the time of year to review feedback from participants and stakeholders, to address those concerns by making adjustment to step sequence, escalation paths, timing, routing, and reporting. If you don’t have a dashboard or some other means for a risk program manager to identify workflow issues and intervene when needed, consider setting up something to make those situations easier to identify. In like manner, you could address any other process workflows in any other areas.</p>
<p>Consider the interfaces your program employs to incorporate data from other sources, i.e., suppliers and partners, regulatory and compliance reviews, internal and external audits, industry data stores (like Dun &amp; Bradstreet), or any others you may use. Have you had any timeliness or interface issues? Is maintenance of these interfaces straightforward? Automated? Do you have clear escalation practices in place if there is a problem? Are these practices documented so backup staff can implement them if necessary? Add these to your review checklist too.</p>
<p>Some other processes to review and tune are end user training, risk assessment, TPRM onboarding, and subject matter expert (SME) reviews wherever they occur. Consider what seemed to be easily grasped by your GRC’s end users, and what required frequent post training support. Also, keep your training aligned with any adjustments made to your processes, features, interfaces, or security provisions. Alterations to user training may have positive impacts upon the performance and experience in those other processes. It’s a good time to examine your risk scoring methods to assure they are clear, make sense for your line of business, and provide a level of clarity and specificity useful to managing the risks under review.</p>
<p>Security is somehow often left behind in these review practices. It shouldn’t be. Your GRC holds a lot of potentially sensitive, and perhaps proprietary data—content you and your partners, clients, customers and stakeholders would not be pleased to openly share. So, are your authentication methods current? How are you segregating and assigning permissions? Do you employ a role based security model? Have you or are you integrating a single sign on (SSO) means of enabling access? How are you administering this? How do you terminate access when the situation merits? Are you using a hosted or cloud based solution? How are you ensuring security there is in line with your needs? Do your processes generate the audit trails and documentation you need to meet regulator’s requirements? Again, tailoring and tuning some of these processes as you look forward to 2022 will add efficiency and strength to your risk management program.</p>
<p><strong><span style="color: #3366ff;">Reporting</span></strong><br>
Some think there can never be too much reporting. I disagree. There is always room for specific targeted reporting that answers important business questions. The rest is just confusing and disruptive volume…noise. Needing or wanting to know “everything” just means you don’t know what’s important. If a report, dashboard, or other information device doesn’t answer this question, consider discontinuing it: “As a result of knowing this information I can and will now take ____ action.” If the report doesn’t answer a clear business question that leads to a decision to act or not in a specific manner, what value does it provide? Proof you could produce the report? So? I’ve seen many businesses buried in reporting while actionable information starved. Don’t become one of these. The practice wastes money, time, and drains valuable resources best applied to other aspects of your program.</p>
<p>Also, look over your access, publication, and distribution processes for the information reporting you create. Does everyone with current access need it? How difficult is it to access if entitled? Do you push reports out to people or post them securely and enable access? Are they produced in formats that support repurposing where and when it might be wanted? Can recipients create their own ad hoc queries? Or drill into or restrict the scope of distributed information?</p>
<p>Last, are the reports free of jargon, clear and easy to understand, and do they provide meaningful, actionable information within the context of your business? Have you asked your key audiences and stakeholders if they might want new, or additional information, in different forms, or in different frequencies? This is a good time to gather such input and plan for any adjustments in the coming year. Don’t hesitate to challenge requests with that key question. It helps avoid what’s referred to as “report creep”.</p>
<p><strong><span style="color: #3366ff;">Alignment To Your Mission</span></strong><br>
Annual goals change, missions are less volatile. Was your risk program aligned with either? Both? How does the configuration and capability of your GRC contribute to your risk program’s support of your company’s mission and goals? One approach you may consider is to list your company’s mission and key goals for the coming year. Then list, based upon your 2021 efforts in cyber and IT risk management, the key risks you determine pose the greatest threats to accomplishing those goals and staying true to the mission. Look at the array. Are there areas where your program has identified risks that are not well addressed, do not have methods and resources to monitor, evaluate, prevent or remediate those threats, should they materialize? There are your “hot spots” for 2022! Would you need assets, features, processes or some combination of them to improve your program’s alignment? This kind of analysis positions requests for resources in the context of the business, bypassing the argument of “professional polishing” of a good program for its own sake. The value of your risk program is in its contribution to your business’ mission and success. This is a way to illustrate where you are, how you contribute (beyond the obvious “keep us safe”), where and why you want to refine the program from its current state.</p>
<p><strong><span style="color: #3366ff;">Looking Ahead…</span></strong><br>
There will always be new challenges, unexpected events, and situations that are completely outside your control you will need to respond to in useful ways. Nobody saw a pandemic coming. Nobody forecasted the “great resignation”, and by sometime very soon there will be additional events or situations to add to that list. Looking forward, assessing risk potential, monitoring the trends of malicious behavior by threat actors inside and outside your company is what cyber risk management is all about. But with careful planning, thoughtful maintenance and refinement of tools, processes and practices, and a critical look to emerging new methods such as AI based monitoring and assessment, digital twins, careful third party management, and automated detection tools, you will position your cyber and IT risk management programs to serve your company, its investors, client and customers well into tomorrow. With a little tailoring, your fit and performance will suit you well, and continue to mature and improve with age.</p>
<p>About the Author:<br>
Simon Goldstein is an accomplished senior executive blending both technology and business expertise to formulate, impact, and achieve corporate strategies. A retired senior manager of Accenture’s IT Security and Risk Management practice, he has achieved results through the creation of customer value, business growth, and collaboration. An experienced change agent with primary experience in financial, technology, and retail industries, he’s led efforts to achieve ISO2700x certification and HIPAA compliance, as well as held credentials of CRISC, CISM, CISA.</p>


<div class="wpforms-container wpforms-container-full" id="wpforms-116"><form id="wpforms-form-116" class="wpforms-validate wpforms-form" data-formid="116" method="post" enctype="multipart/form-data" action="/category/audit-management/feed/" data-token="d586098de15a2a4bd6cd724c5ceb7f9a" data-token-time="1785609587"><div class="wpforms-head-container"><div class="wpforms-title">Newsletter Signup</div><div class="wpforms-description">Interested in being informed when a new blog post is released?</div></div><noscript class="wpforms-error-noscript">Please enable JavaScript in your browser to complete this form.</noscript><div class="wpforms-field-container"><div id="wpforms-116-field_0-container" class="wpforms-field wpforms-field-name" data-field-id="0"><label class="wpforms-field-label" for="wpforms-116-field_0">Name <span class="wpforms-required-label">*</span></label><div class="wpforms-field-row wpforms-field-medium"><div class="wpforms-field-row-block wpforms-first wpforms-one-half"><input type="text" id="wpforms-116-field_0" class="wpforms-field-name-first wpforms-field-required" name="wpforms[fields][0][first]" required><label for="wpforms-116-field_0" class="wpforms-field-sublabel after">First</label></div><div class="wpforms-field-row-block wpforms-one-half"><input type="text" id="wpforms-116-field_0-last" class="wpforms-field-name-last wpforms-field-required" name="wpforms[fields][0][last]" required><label for="wpforms-116-field_0-last" class="wpforms-field-sublabel after">Last</label></div></div></div>		<div id="wpforms-116-field_4-container"
			class="wpforms-field wpforms-field-text"
			data-field-type="text"
			data-field-id="4"
			>
			<label class="wpforms-field-label" for="wpforms-116-field_4" >Name Company Email</label>
			<input type="text" id="wpforms-116-field_4" class="wpforms-field-medium" name="wpforms[fields][4]" >
		</div>
		<div id="wpforms-116-field_1-container" class="wpforms-field wpforms-field-email" data-field-id="1"><label class="wpforms-field-label" for="wpforms-116-field_1">Email <span class="wpforms-required-label">*</span></label><input type="email" id="wpforms-116-field_1" class="wpforms-field-medium wpforms-field-required" name="wpforms[fields][1]" spellcheck="false" required></div><div id="wpforms-116-field_2-container" class="wpforms-field wpforms-field-text" data-field-id="2"><label class="wpforms-field-label" for="wpforms-116-field_2">Company</label><input type="text" id="wpforms-116-field_2" class="wpforms-field-medium" name="wpforms[fields][2]" ></div><div id="wpforms-116-field_3-container" class="wpforms-field wpforms-field-text" data-field-id="3"><label class="wpforms-field-label" for="wpforms-116-field_3">Title</label><input type="text" id="wpforms-116-field_3" class="wpforms-field-medium" name="wpforms[fields][3]" ></div><script>
				( function() {
					const style = document.createElement( 'style' );

					style.appendChild( document.createTextNode( '#wpforms-116-field_4-container { position: absolute !important; overflow: hidden !important; display: inline !important; height: 1px !important; width: 1px !important; z-index: -1000 !important; padding: 0 !important; } #wpforms-116-field_4-container input { visibility: hidden; } #wpforms-conversational-form-page #wpforms-116-field_4-container label { counter-increment: none; }' ) );
					document.head.appendChild( style );
					document.currentScript?.remove();
				} )();
			</script></div><!-- .wpforms-field-container --><div class="wpforms-field wpforms-field-hp"><label for="wpforms-116-field-hp" class="wpforms-field-label">Name</label><input type="text" name="wpforms[hp]" id="wpforms-116-field-hp" class="wpforms-field-medium"></div><div class="wpforms-submit-container" ><input type="hidden" name="wpforms[id]" value="116"><input type="hidden" name="page_title" value="Audit Management"><input type="hidden" name="page_url" value="https://www.doublechecksoftware.com/category/audit-management/feed/"><button type="submit" name="wpforms[submit]" id="wpforms-submit-116" class="wpforms-submit" data-alt-text="Sending..." data-submit-text="Keep Me Informed" aria-live="assertive" value="wpforms-submit">Keep Me Informed</button></div></form></div>  <!-- .wpforms-container --><p>The post <a href="https://www.doublechecksoftware.com/when-comes-december-tailoring-your-grc-programs-for-the-coming-year/">When Comes December; Tailoring Your GRC Programs For The Coming Year</a> first appeared on <a href="https://www.doublechecksoftware.com">DoubleCheck Software</a>.</p>]]></content:encoded>
					
					<wfw:commentRss>https://www.doublechecksoftware.com/when-comes-december-tailoring-your-grc-programs-for-the-coming-year/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2750</post-id>	</item>
		<item>
		<title>Summertime, And The Cyber Risk Is Easy…</title>
		<link>https://www.doublechecksoftware.com/summertime-and-the-cyber-risk-is-easy/</link>
					<comments>https://www.doublechecksoftware.com/summertime-and-the-cyber-risk-is-easy/#respond</comments>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Mon, 02 Aug 2021 12:37:35 +0000</pubDate>
				<category><![CDATA[Audit Management]]></category>
		<category><![CDATA[Cyber Security Risk Management]]></category>
		<category><![CDATA[Enterprise Risk Management]]></category>
		<category><![CDATA[GRC Implementation Success]]></category>
		<category><![CDATA[TPRM]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Third Party Risk Management]]></category>
		<category><![CDATA[TPRM Software]]></category>
		<category><![CDATA[Vendor Risk Management]]></category>
		<guid isPermaLink="false">https://www.doublechecksoftware.com/?p=2688</guid>

					<description><![CDATA[<p>Summertime, and the living is, once again, easy—sort of. Just a few summers ago these were the days of occasional remote work, long weekends, holidays, vacations, and for some companies, shortened “summer hours”. As our work routines have made the separation of office, work, and personal time a fluid continuum, our risk perimeter and footprint<a href="https://www.doublechecksoftware.com/summertime-and-the-cyber-risk-is-easy/">[...]</a></p>
<p>The post <a href="https://www.doublechecksoftware.com/summertime-and-the-cyber-risk-is-easy/">Summertime, And The Cyber Risk Is Easy…</a> first appeared on <a href="https://www.doublechecksoftware.com">DoubleCheck Software</a>.</p>]]></description>
										<content:encoded><![CDATA[<p>Summertime, and the living is, once again, easy—sort of. Just a few summers ago these were the days of occasional remote work, long weekends, holidays, vacations, and for some companies, shortened “summer hours”. As our work routines have made the separation of office, work, and personal time a fluid continuum, our risk perimeter and footprint have become increasingly complex, and flexible. The constraints of COVID-19 isolation throughout most of 2020 and into 2021 masked some of the vectors and prevented some of the situations we all commonly attended to in prior years. When you are predominantly home, so are all your mobile devices. And episodic journeys for food or other supplies rarely required hoisting an assembly of mobile devices along for the journey—a mobile phone, smart watch, or maybe a tablet, at most.</p>
<p>Now, we are “out” again—sort of. Working remotely at coffee shops, on beaches, travelling through airports, on cruises, aloft in airplanes, sleeping in hotels, meeting in restaurants and cafes. And, since much of our knowledge worker staff were part of that “work from home” crowd of the past year’s sequester, we are out and about with all our portable tech, connecting via public WIFI, and perhaps not being in practice to pay rigorous attention to the rules, policies, and best practices so many of our firms worked to instill in the hearts and minds of those of us who can be remote. This presents a rich opportunity for malicious actors who see a population whose guard may be temporarily down, who may behave in ways that open doors to all sorts of vulnerabilities. These could include ransomware, hacks and breeches of all sorts, stolen devices containing sensitive or proprietary data, malware injections, and phishing attacks, and more.</p>
<p><strong><span style="color: #3366ff;">A Proactive Approach</span></strong><br>There are four (4) actions to take at a minimum to address these concerns.</p>
<ul>
<li>Revisit your related policies</li>
<li>Republish key policies, re-educate your workforce and promote best practices for remote working</li>
<li>Review and reassess your controls and monitoring methods</li>
<li>Monitor your third party partners, vendors, and suppliers</li>
</ul>
<p>Let’s look a bit more in detail at each, and see how your best practices for managing cyber risk can be applied to this somewhat unique moment in time not anticipated by anyone in the recent past.</p>
<p><strong><span style="color: #3366ff;">Revisit your related policies</span></strong><br>You may have completed a cycle of review at the beginning of the 2020 pandemic. Still, that was with consideration to a substantially remote-in-place workforce. The attention then was to remote device management, WIFI connectivity, access controls, phishing, and perhaps data management practices. In addition, now the best practices for handling those devices in travel situations, use of flash storage devices, physical security when working in public areas, and best practices for storing devices in vehicles or hotels while on the road become concerns again. Small, portable storage devices such as flash drives have become convenient, and somewhat ubiquitous parts of everyday mobile computing. Do you have policies and monitoring practices to manage the use of only authorized devices, ones that are encrypted and only applied to machines under your mobile device management control? Is business use of personal computing devices permitted by policy? What other provisions for remote, but relatively isolated and stationary working were made during the height of the pandemic? Were they temporary or permanent policy adjustments? What exposure does the return to mobility create while these policy and practice adjustments remain in force?</p>
<p><strong><span style="color: #3366ff;">Republish, Re-educate, and Promote</span></strong><br>There’s never a bad time to remind everyone of important policy provisions—particularly during periods of frequent, substantial change. Those are times when confusion is at its peak, and clarity is particularly valuable. Use this opportunity to refresh awareness of policies that seemed irrelevant during the constraints of living and working under a pandemic’s restricted mobility. People’s attention may have contracted substantially during that period, and security practices, provisions, and cautions unexercised may have become weak over the past year.</p>
<p>This offers an excellent opportunity to offer a fresh round of end user training to remind staff of basic policies and practices, care for mobile devices while traveling, rules for remote data handling, and so forth. It’s also a good idea to test how well people respond to potential phishing and social engineering scenarios. The feedback and test results of these efforts can be factored into your overall cyber risk and security assessments; comparing current results with past cycles to identify weaknesses and prepare to address/reinforce vulnerable behavior.</p>
<p>Internal promotion of security and cyber best practices, warnings about phishing and malicious social engineering efforts aren’t often recognized as effective cyber risk strategies. But well crafted, short, focused and direct messaging can be effective educational tools that support learning. Such messaging, whether delivered by email, through wall posters, or short videos posted online can effectively sharpen staff attention to security practices and skills that may have been overlooked in the past year.</p>
<p><strong><span style="color: #3366ff;">Review, Reassess Controls And Monitoring Methods</span></strong><br>While looking at your policies, also examine the effectiveness of your controls. Are you following a framework such as NIST Cyber Security, COBIT, or HITECH, to name a few? If so, are there new control or revisions to the framework you follow that require incorporation into your risk program. Some frameworks issue guidance on how to handle certain controls. Examine these frameworks to identify controls most likely to have been attended to in a lax manner or seemed less important in the last year. Look at the data from your most recent controls assessment. Were there controls that were frequently left aside, replaced by ad-hoc compensating practices, or frankly ignored? If there are some that many areas reported as unpracticed, you might want to look at their appropriateness to your business processes.</p>
<p>Do your monitoring processes and tools give you the coverage and real time alertness you need to identify and respond to threats as soon as they are detected? How have you adjusted your monitoring devices and alert filters to detect and identify low frequency anomalies? Have you deployed procedures and tools to support remote users’ access to your network via VPN services? Are these appropriately sized to service growing demand? How are you monitoring confidential information flows? Have you deployed a data loss prevention (DLP) solution? And, how are you monitoring the activity and access of your third parties—not just the “vendors”, but the professional service providers, logistics services, and more subject to consideration. And, in some regards, the remote working environment has evolved since the pandemic began. Services such as Amazon’s Sidewalk are now present, offering a blended, and further blurry determination of connection points and the boundaries extended by staff working at home. The continued proliferation of IoT devices has created new vulnerabilities and opportunities for malicious actor entry to your world. Such dynamic change cannot be ignored.</p>
<p><strong><span style="color: #3366ff;">Monitor Your Third Party Partners, Vendors, And Suppliers</span></strong><br>When people mention third parties, they often presume vendors. While that’s true, it’s an incomplete description of the categorization. Do you include your service providers, from building maintenance, gardening, HVAC, and general repair in this category? How about delivery services where you have some online interaction? Do some of the services, including professional services, rely upon sub-contractors to fulfill commitments to you (of particular importance if you are subject to HIPAA or HITECH compliance)? Virtually any service that provides electronic invoicing, or provision of services that includes communication through electronic means, even if there is no authenticated access to your network, or exchange of data, should be subject to some measure of care and monitoring to effectively protect your own business. As the world begins to reopen, vigilance of travel, transportation, and hospitality services that were all but eliminated from necessary consideration now must be restored. The category of third party is widely larger than material or service providers alone.</p>
<p><strong><span style="color: #3366ff;">Knowing Where You Stand</span></strong><br>So, how do you know where you are with regard to all that’s noted above? It can seem like a lot to track, to monitor, to review, and to analyze. And, it’s why for the growing or well established concern, the acquisition and deployment of a GRC platform becomes an asset rather than an expense. A quality platform can offer the means to function as an information “manifold” to serve as an authoritative point of reference for information, status, and planning for all your risk activities, while relating and leveraging other processes whose information products inform your risk management, whether it be focused upon cyber, financial, third-party, IT, operational, or more. Most importantly, a quality GRC automates routine tasks, reduces the labor footprint needed to manage and coordinate all the activities necessary to manage company risk, while keeping executive leadership informed of current issues, vulnerabilities and opportunities so resources can most effectively be made available. It can also extend these benefits to related practices, such as Audit, and Compliance, further increasing the value/expense benefits provided. Such a platform supports the reuse and leveraging of data gathered through one process area, such as Audit, in areas such as Compliance or Risk. This capability represents an expression of value that exceeds any base monetized calculations of operating savings. It represents real efficiency offering more timely access to reliable information. As the world grows more complex, and the pace of change increases, quicker access to reliable information will become an increasingly valuable strategic and operating advantage to your business and the clients and customers you serve.</p>
<p>About the Author:<br>Simon Goldstein is an accomplished senior executive blending both technology and business expertise to formulate, impact, and achieve corporate strategies. A retired senior manager of Accenture’s IT Security and Risk Management practice, he has achieved results through the creation of customer value, business growth, and collaboration. An experienced change agent with primary experience in financial, technology, and retail industries, he’s led efforts to achieve ISO2700x certification and HIPAA compliance, as well as held credentials of CRISC, CISM, CISA.</p>


<div class="wpforms-container wpforms-container-full" id="wpforms-116"><form id="wpforms-form-116" class="wpforms-validate wpforms-form" data-formid="116" method="post" enctype="multipart/form-data" action="/category/audit-management/feed/" data-token="d586098de15a2a4bd6cd724c5ceb7f9a" data-token-time="1785609587"><div class="wpforms-head-container"><div class="wpforms-title">Newsletter Signup</div><div class="wpforms-description">Interested in being informed when a new blog post is released?</div></div><noscript class="wpforms-error-noscript">Please enable JavaScript in your browser to complete this form.</noscript><div class="wpforms-field-container"><div id="wpforms-116-field_0-container" class="wpforms-field wpforms-field-name" data-field-id="0"><label class="wpforms-field-label" for="wpforms-116-field_0">Name <span class="wpforms-required-label">*</span></label><div class="wpforms-field-row wpforms-field-medium"><div class="wpforms-field-row-block wpforms-first wpforms-one-half"><input type="text" id="wpforms-116-field_0" class="wpforms-field-name-first wpforms-field-required" name="wpforms[fields][0][first]" required><label for="wpforms-116-field_0" class="wpforms-field-sublabel after">First</label></div><div class="wpforms-field-row-block wpforms-one-half"><input type="text" id="wpforms-116-field_0-last" class="wpforms-field-name-last wpforms-field-required" name="wpforms[fields][0][last]" required><label for="wpforms-116-field_0-last" class="wpforms-field-sublabel after">Last</label></div></div></div>		<div id="wpforms-116-field_4-container"
			class="wpforms-field wpforms-field-text"
			data-field-type="text"
			data-field-id="4"
			>
			<label class="wpforms-field-label" for="wpforms-116-field_4" >Company Email Title</label>
			<input type="text" id="wpforms-116-field_4" class="wpforms-field-medium" name="wpforms[fields][4]" >
		</div>
		<div id="wpforms-116-field_1-container" class="wpforms-field wpforms-field-email" data-field-id="1"><label class="wpforms-field-label" for="wpforms-116-field_1">Email <span class="wpforms-required-label">*</span></label><input type="email" id="wpforms-116-field_1" class="wpforms-field-medium wpforms-field-required" name="wpforms[fields][1]" spellcheck="false" required></div><div id="wpforms-116-field_2-container" class="wpforms-field wpforms-field-text" data-field-id="2"><label class="wpforms-field-label" for="wpforms-116-field_2">Company</label><input type="text" id="wpforms-116-field_2" class="wpforms-field-medium" name="wpforms[fields][2]" ></div><div id="wpforms-116-field_3-container" class="wpforms-field wpforms-field-text" data-field-id="3"><label class="wpforms-field-label" for="wpforms-116-field_3">Title</label><input type="text" id="wpforms-116-field_3" class="wpforms-field-medium" name="wpforms[fields][3]" ></div><script>
				( function() {
					const style = document.createElement( 'style' );

					style.appendChild( document.createTextNode( '#wpforms-116-field_4-container { position: absolute !important; overflow: hidden !important; display: inline !important; height: 1px !important; width: 1px !important; z-index: -1000 !important; padding: 0 !important; } #wpforms-116-field_4-container input { visibility: hidden; } #wpforms-conversational-form-page #wpforms-116-field_4-container label { counter-increment: none; }' ) );
					document.head.appendChild( style );
					document.currentScript?.remove();
				} )();
			</script></div><!-- .wpforms-field-container --><div class="wpforms-field wpforms-field-hp"><label for="wpforms-116-field-hp" class="wpforms-field-label">Message</label><input type="text" name="wpforms[hp]" id="wpforms-116-field-hp" class="wpforms-field-medium"></div><div class="wpforms-submit-container" ><input type="hidden" name="wpforms[id]" value="116"><input type="hidden" name="page_title" value="Audit Management"><input type="hidden" name="page_url" value="https://www.doublechecksoftware.com/category/audit-management/feed/"><button type="submit" name="wpforms[submit]" id="wpforms-submit-116" class="wpforms-submit" data-alt-text="Sending..." data-submit-text="Keep Me Informed" aria-live="assertive" value="wpforms-submit">Keep Me Informed</button></div></form></div>  <!-- .wpforms-container --><p>The post <a href="https://www.doublechecksoftware.com/summertime-and-the-cyber-risk-is-easy/">Summertime, And The Cyber Risk Is Easy…</a> first appeared on <a href="https://www.doublechecksoftware.com">DoubleCheck Software</a>.</p>]]></content:encoded>
					
					<wfw:commentRss>https://www.doublechecksoftware.com/summertime-and-the-cyber-risk-is-easy/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2688</post-id>	</item>
		<item>
		<title>Integrating Audit and Cyber Risk Management Processes to Address AI Risks</title>
		<link>https://www.doublechecksoftware.com/integrating-audit-and-cyber-risk-management-processes-to-address-ai-risks/</link>
					<comments>https://www.doublechecksoftware.com/integrating-audit-and-cyber-risk-management-processes-to-address-ai-risks/#respond</comments>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Mon, 02 Mar 2020 14:24:26 +0000</pubDate>
				<category><![CDATA[Audit Management]]></category>
		<category><![CDATA[Cyber Security Risk Management]]></category>
		<category><![CDATA[GRC Implementation Success]]></category>
		<guid isPermaLink="false">https://www.doublechecksoftware.com/?p=1541</guid>

					<description><![CDATA[<p>Audit and risk management are really two perspectives or “flavors” of the same measurement and inspection processes. In blogs of October and November 2018, I’ve discussed some of the key aspects of these processes and offered some arguments for the benefit of their integration to offer executive management a sharper picture of their true risk<a href="https://www.doublechecksoftware.com/integrating-audit-and-cyber-risk-management-processes-to-address-ai-risks/">[...]</a></p>
<p>The post <a href="https://www.doublechecksoftware.com/integrating-audit-and-cyber-risk-management-processes-to-address-ai-risks/">Integrating Audit and Cyber Risk Management Processes to Address AI Risks</a> first appeared on <a href="https://www.doublechecksoftware.com">DoubleCheck Software</a>.</p>]]></description>
										<content:encoded><![CDATA[<p>Audit and risk management are really two perspectives or “flavors” of the same measurement and inspection processes. In blogs of October and November 2018, I’ve discussed some of the key aspects of these processes and offered some arguments for the benefit of their integration to offer executive management a sharper picture of their true risk position and the effectiveness of controls in place. If you’ve not read them, please look back for some of the foundational arguments assumed here.</p>
<p>Articles abound today in Forbes, in the Wall Street Journal, from large consulting firms, and business schools, (i.e., Accenture, Deloitte, and Kellogg) addressing artificial intelligence (AI) and its impact upon risk management. Some talk about the risks of AI technology, others about how AI will enrich risk management. They all offer insight to technological directions and strategies well suited to large firms with ample financial and human talent resources dedicated to taking leadership actions in this emerging arena. To be frank, we are all surrounded by emerging AI of different capabilities in different places. Staff working at home, surrounded by “smart” appliances, voice activated devices, and new TV’s to name a few are all capable of “seeing” and “listening” to the activity around them; gathering this data and storing it in some provider’s cloud.&nbsp; This is just one example. Mobile devices are another source of AI “opportunity”.</p>
<p>So, what’s a company to do when they do not have the robust financial and talent resources to acquire and apply AI tools and services to their risk management efforts right now? They take advantage of tools in place, thoughtfully applied, to gain some measure of closure against these possibilities.&nbsp; AI is in large measure about the ability to churn through endless mountains of data to find obscure but significant trends or associations that would otherwise be difficult to discover. It’s also about machine learning, which also involves massive but efficient data churning and pattern detection and response. AI is not magic. Often, at its roots, it’s not even science, but algorithmic muscling through these data stores. Well, there is some science in specialized hardware like LIDAR, (Light Detection and Ranging) used in smart cars, but we’re not going there here.</p>
<p>If you have a GRC platform solution in place for risk assessment and management, accompanied by or (better) integrated with an effective internal audit process, you have the foundations of data stores needed to address some of these newer threat and risk vectors potentially impacting your business. This affords you the opportunity to use data analysis tools help you achieve some very useful and directive results for your risk program. If your current GRC doesn’t incorporate such tools there are numerous OTC solutions available.</p>
<p><img loading="lazy" decoding="async" class="alignnone  wp-image-1548" src="https://www.doublechecksoftware.com/wp-content/uploads/2020/02/blog-12-graphic-300x223.jpg" alt="" width="563" height="418" srcset="https://www.doublechecksoftware.com/wp-content/uploads/2020/02/blog-12-graphic-300x223.jpg 300w, https://www.doublechecksoftware.com/wp-content/uploads/2020/02/blog-12-graphic-150x112.jpg 150w, https://www.doublechecksoftware.com/wp-content/uploads/2020/02/blog-12-graphic-768x572.jpg 768w, https://www.doublechecksoftware.com/wp-content/uploads/2020/02/blog-12-graphic-1024x762.jpg 1024w, https://www.doublechecksoftware.com/wp-content/uploads/2020/02/blog-12-graphic.jpg 1065w" sizes="(max-width: 563px) 100vw, 563px" /></p>
<p style="padding-left: 150px;"><b><i>Basic integration of Risk and Audit at the Results Level</i></b></p>
<p>Good reporting answers business questions leading to actionable direction.&nbsp; Some of the key questions to be explored for any cyber risk management program would include these:</p>
<ul>
<li>What threats pose the greatest risk to our business?</li>
<li>What have we done to reduce the risk posed by these threats?</li>
<li>Are these controls in force and effective? How do we know?</li>
<li>Have we done enough? What is our risk appetite?</li>
<li>Are we compliant with commitments in place through regulation and contractual obligation?</li>
<li>Do we have the resources to assure risk is managed within our needs?</li>
<li>What processes are in place to identify and manage incidents or breaches when they occur?</li>
</ul>
<p>The data combined from risk management and audit processes is not the complete set of information a risk solution aided by AI analysis processes could handle.&nbsp; There are external factors, such as marketplace data, client or customer data, financial and competitive inputs that might also impact comprehensive inputs to threat or risk identification.&nbsp; But the pair of audit and risk can provide a strong basis for threat identity and risk management. You’ll be able to know what the state of threat identification is within your enterprise. How well current controls address risk mitigation will be clear to see. Risks remaining in place with no apparent management strategy should also be straightforward to identify. Sharing these data with your executive team will enable clear, well informed decisions regarding your current risk position.</p>
<p>The risks and threats associated with the use of AI operationally can be addressed within standard enterprise risk management (ERM) frameworks if you treat the use of AI technologies within your firm as just one more potential source of risk.&nbsp; The core processes of identification, response, remediation, and such apply to risks associated with threats and attacks employing AI technologies, whether they originate from the operational use of AI by your enterprise, or from attacks enabled through its use by threat actors. This doesn’t mean you should avoid employing AI powered risk technologies when you can, but need to understand fully what they might do, how they work, and how to manage any inherent bias in the algorithms they employ.</p>
<p>Commercial products are often designed to meet a wide swath of market and industry needs.&nbsp; To do that, some assumptions are likely made about how those businesses behave, how their customers interact, what transactions are most “common”, and what threats are most likely present. These assumptions naturally establish some biases that can often be tuned through configuration, but still impact the results of any data analysis.&nbsp; So, employing such tools needs to include a thorough review of risks associated with the application of AI. Inherit bias in operations or in risk management tools also exists outside the AI sphere, but human intervention, operation, and interpretation of results often counteract those attributes.</p>
<p>One way to integrate audit, security, and cyber risk is through common controls mapping—understanding which activities and controls contribute to more than one operational or regulatory compliance obligation, security best practice, or help thwart a malicious threat. Looking for consistent patterns in these controls, and then in the data resulting from audit findings, the state of remediation efforts, the frequency of discovery of weak or inadequate findings can all point to trends useful to managing your overall enterprise risk posture.&nbsp; While AI risk management tools might help automate some of this analysis, these tools are data consumers, and do not have the ability to apply the inherent human knowledge, comprehension, and experience with the operation and performance of any particular business.&nbsp; For that, experienced human review and interpretation of the data, however arrayed or combined, remains an invaluable contributor to comprehensive data analysis, and the resulting risk identification process.</p>
<p>The common data stores offered by consolidating data from many sources into an AI tool, or through an integrated GRC program with internal and external audit processes, will both lead to opportunity for better informed understanding of enterprise risk and the effectiveness of controls and remediations set forth to address foreseen threats. As always, there are multiple approaches and paths to achieve these informed ends.&nbsp; AI is useful for large businesses with complex and extensive risk footprints and trained staff to manage these tools, and interpret their findings.&nbsp; Firms with less complicated circumstances employing strong audit programs and supported by GRC technologies to help consolidate, integrate, and evaluate results from these program activities may be able to achieve much the same ends.&nbsp; Both approaches benefit from oversight and results interpretation by experienced, knowledgeable people, who can employ what they know to filter inherit bias while taking advantage of the best information before them.&nbsp; Likewise, as a check or control of human bias, consolidated data from multiple sources helps strengthen arguments for new discovery or positions previously downplayed or ignored because of past practice, habit, or management preferences to date.</p>
<p>Together, consolidating, integrated technologies offer better opportunities for sound risk and security management than siloed disciplines reporting separately and operating independently. They help prevent needless duplication and redundancy of effort, reduce operating overhead, and lead to more complete and comprehensive solutions to address weaknesses and confirm strengths in your risk management program. Artificial intelligence, whether employed to support operational business transactions, or to evaluate risk, will grow in utility and reliability as technology matures.&nbsp; Meanwhile, its current state will continue to offer risk opportunities for enterprises to resolve. Creative, thoughtful deployment of well vetted and reliable GRC and audit tools will continue to provide sound risk management information to support enterprise leaders’ informed decisions for some time to come.</p>
<p><em>About the Author:</em></p>
<p>Simon Goldstein is an accomplished senior executive blending both technology and business expertise to formulate, impact, and achieve corporate strategies. A retired senior manager of Accenture’s IT Security and Risk Management practice, he has achieved results through the creation of customer value, business growth, and collaboration. An experienced change agent with primary experience in financial, technology, and retail industries, he’s led efforts to achieve ISO2700x certification and HIPAA compliance, as well as held credentials of CRISC, CISM, CISA.</p>


<p></p><p>The post <a href="https://www.doublechecksoftware.com/integrating-audit-and-cyber-risk-management-processes-to-address-ai-risks/">Integrating Audit and Cyber Risk Management Processes to Address AI Risks</a> first appeared on <a href="https://www.doublechecksoftware.com">DoubleCheck Software</a>.</p>]]></content:encoded>
					
					<wfw:commentRss>https://www.doublechecksoftware.com/integrating-audit-and-cyber-risk-management-processes-to-address-ai-risks/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">1541</post-id>	</item>
		<item>
		<title>Applying NIST Standards to Managing Cyber Risk and Regulatory Compliance</title>
		<link>https://www.doublechecksoftware.com/applying-nist-standards-to-managing-cyber-risk-and-regulatory-compliance/</link>
					<comments>https://www.doublechecksoftware.com/applying-nist-standards-to-managing-cyber-risk-and-regulatory-compliance/#respond</comments>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Tue, 28 May 2019 14:23:30 +0000</pubDate>
				<category><![CDATA[Audit Management]]></category>
		<category><![CDATA[Cyber Security Risk Management]]></category>
		<category><![CDATA[Enterprise Risk Management]]></category>
		<guid isPermaLink="false">https://www.doublechecksoftware.com/?p=1359</guid>

					<description><![CDATA[<p>In our last blog, we explored the content and value of the New York State Department Of Financial Services 23 NYCRR 500; Cybersecurity Requirements For Financial Services Companies. In this article, we’ll explore how the application of a framework like NIST 800-53, or the NIST Cybersecurity Framework helps structure and achieve strong compliance with regulations<a href="https://www.doublechecksoftware.com/applying-nist-standards-to-managing-cyber-risk-and-regulatory-compliance/">[...]</a></p>
<p>The post <a href="https://www.doublechecksoftware.com/applying-nist-standards-to-managing-cyber-risk-and-regulatory-compliance/">Applying NIST Standards to Managing Cyber Risk and Regulatory Compliance</a> first appeared on <a href="https://www.doublechecksoftware.com">DoubleCheck Software</a>.</p>]]></description>
										<content:encoded><![CDATA[<p>In our last blog, we explored the content and value of the New York State Department Of Financial Services 23 NYCRR 500; <u>Cybersecurity Requirements For Financial Services Companies</u>. In this article, we’ll explore how the application of a framework like NIST 800-53, or the NIST Cybersecurity Framework helps structure and achieve strong compliance with regulations like this one.</p>



<p>Let’s
review what this regulation, enacted into effect in March of 2017, puts forth
for financial services throughout NY State.</p>



<p>It
begins by acknowledging the growing threat of cyber-attacks and setting forth
the regulation’s intent; summarized by these points:</p>



<ul class="wp-block-list"><li><em>Promote the protection of customer information and IT
systems</em> of
regulated entities</li><li><em>Proscribe regulatory minimum standards</em></li><li><em>Allow cybersecurity programs to match the relevant
risks</em> and
keep pace with technological advances.</li><li><em>Require each company to assess its specific risk profil</em>e and design a program that
addresses its risks in a robust fashion.</li><li><em>Set Senior Management responsibility</em> for the organization’s
cybersecurity program</li><li><em>Require Covered Entities to file an annual
certification</em> confirming compliance with these regulations.<br>
<br>
</li></ul>



<p>While these points set forth foundational, core
requirements and expectations, they bear a strong resemblance in language and
intent to the primary components of the NIST Cybersecurity Framework, and now
to the proposed revisions to NIST Security Standard 800-53 rev5. And, they offer common ground
between what a cyber risk professional would view as requirements for a
professionally managed cyber risk program.&nbsp;
They also, through the specific details of control requirements noted in
the regulation, describe minimal compliance activity.&nbsp; NIST 88-53 Rev4 and 5 are built around a
tiered approach to structuring information systems security, while offering 18
control families to be addressed, specifically:<br>
<br>
</p>



<ul class="wp-block-list"><li>Tier 1 – The Organization</li><li>Tier 2 – Business Processes</li><li>Tier 3 – Information Systems&nbsp; </li></ul>



<p>And…</p>



<div class="wp-block-image"><figure class="alignright is-resized"><img loading="lazy" decoding="async" src="https://www.doublechecksoftware.com/wp-content/uploads/2019/05/Control-Family-table.jpg" alt="" class="wp-image-1362" width="425" height="288" srcset="https://www.doublechecksoftware.com/wp-content/uploads/2019/05/Control-Family-table.jpg 662w, https://www.doublechecksoftware.com/wp-content/uploads/2019/05/Control-Family-table-150x102.jpg 150w, https://www.doublechecksoftware.com/wp-content/uploads/2019/05/Control-Family-table-300x204.jpg 300w" sizes="(max-width: 425px) 100vw, 425px" /></figure></div>



<p>Numerous detail controls are noted
within the standard utilizing this tiered approach to organization. In
conjunction with this, a draft Special Publication known as the (SP) 800-37
Revision 2, and several other Federal standards combine to offer a Cyber
Security Risk Framework, noting six (6) core steps:</p>



<p></p>



<ul class="wp-block-list"><li>Step 1 – CATAGORIZE Information Systems (FIPS 199/SP
800-60) – IMPACT ASSESSMENT</li><li>Step 2 – SELECT Security Controls (FIPS 200/SP 800-53)</li><li>Step 3 – IMPLEMENT Security Controls (SP 800-160)</li><li>Step 4 – ASSESS Security Controls (SP 800-53A)</li><li>Step 5 – AUTHORIZE Information Systems (SP 800-37)</li><li>Step 6 – MONITOR Security Controls (SP 800-137) </li></ul>



<p></p>



<p>This compares well to the NIST CyberSecurity Framework and its core organizing process categories:</p>



<div class="wp-block-image"><figure class="alignleft is-resized"><img loading="lazy" decoding="async" src="https://www.doublechecksoftware.com/wp-content/uploads/2019/05/NIST-circle.jpg" alt="" class="wp-image-1368" width="281" height="270" srcset="https://www.doublechecksoftware.com/wp-content/uploads/2019/05/NIST-circle.jpg 414w, https://www.doublechecksoftware.com/wp-content/uploads/2019/05/NIST-circle-150x144.jpg 150w, https://www.doublechecksoftware.com/wp-content/uploads/2019/05/NIST-circle-300x288.jpg 300w" sizes="(max-width: 281px) 100vw, 281px" /></figure></div>



<p>All of these standards represent efforts to place scores of detailed, process-oriented security or risk management control practices into an organized structure that makes sense to business leaders outside the professional domains of information services, technology, and cyber risk management. Business-oriented organization of these control, risk, and security practices is essential to enabling useful cross domain conversations and decisions about significance, risk, priority, resource allocation and alignment to organizational goals. It supports creation and application of a standardized, common taxonomy for these discussions, regardless of the details applicable to any single practice, or the technological know-how needed to assure their effective implementation. </p>



<p> </p>



<p></p>



<p>Most organizations with regulatory obligations of any substance benefit from these kinds of organizing frameworks in these 10 ways by:</p>



<ul class="wp-block-list"><li>providing a common structure for comparing regulatory requirements and identifying common controls.</li><li>offering a common terminology to discuss regulatory, security, and risk management requirements and activities.</li><li>simplifying the identification and justification for remediation activities that benefit compliance, security, and risk management, often offering efficiencies where one set of actions achieves a benefit in more than one area.</li><li>enabling efficient and effective allocation of resources to best protect the information assets of an organization, its members, staff, and clients or customers.</li><li>providing a common means to apply best practices for security, risk, and operations methodologies in unregulated businesses, assuring customers their information is protected in a rigorous manner.</li><li>promoting comprehensive internal services to address risk, security, and compliance</li><li>helping organizations sustain currency in best practices regarding risk, security, and compliance.</li><li>recognizing and leveraging the benefits of common controls across multiple processes, disciplines, and regulatory requirements.</li><li>comparison to peers and competitors within your vertical, whatever the dimension</li><li>ready identification of best practices applicable to your most important concerns</li></ul>



<p>Regardless of what path an organization takes, there is
clearly a great deal of data that needs to be gathered, managed, organized,
stored, and analyzed to support the fundamental processes of cyber risk
management, information security, and regulatory compliance.&nbsp; Any single one would create significant need
for structure and careful oversight. The presence of all three greatly increases
that workload.&nbsp; </p>



<p>Some small firms will try to do this using home-grown
tools.&nbsp; I’ve seen many examples of
“Management-by-Excel” to address cyber risk, IT risk, regulatory requirement
compliance, assessments, remedial action tracking, and reporting on all these
fronts. Audit is another area where this malady sometimes takes root. Frankly,
even the best of these “solutions” was largely undocumented, required constant
attention by its creator, and offered little flexibility to address the
changing requirements each of these disciplines is subject to address. It may
be a great way to organize thoughts and represent portions of frameworks as
they are described to fit an organization’s culture, internal taxonomy, or
scope of business. And, it’s good way to organize initial thinking about these
risk management practices. But such solutions are not sustainable, responsive
to rapid change, nor are they readily extensible. </p>



<p>The advantages offered through using a framework are
often best exploited through the implementation of a comprehensive GRC (Governance,
Risk, and Compliance) software platform.&nbsp;
In fact, establishment of a program founded upon a framework, even one
customized through the adoption of common controls across several standards,
actually makes GRC implementation more straightforward. These tools are
designed to work with frameworks.&nbsp; They
often can be delivered preconfigured with one or more standards, and some will
support creation of customized ones through “cherry-picking” of common controls
in conjunction with standard frameworks from other company or regulatory requirements.&nbsp; But that’s just to start. GRC tools are
platforms for leveraging standards and other control sets to facilitate risk
assessments, audits, compliance reviews, and more.&nbsp; </p>



<p>They provide tools for recording remedial activities, (both
against audit findings and risk assessments of all kinds), tracking progress of
related projects, correlating data from one process or operating discipline with
another to cross-validate risk or audit findings, while relating all this
accumulated data into meaningful status and state reports managers and
executives can use to make informed decisions.&nbsp;
GRC tools and features, properly applied, can lead to greater
compliance, security, and operating effectiveness while establishing a means of
directing and monitoring cost effective management for IT, operating, and cyber
risk, audit, regulatory compliance, and operations.&nbsp; They support creation of standardized,
methodical, documented, repeatable practices that can be managed with equal
efficiency in centralized or distributed organizations. They scale. And they
are engineered to be flexibly responsive to change. And they can be secured.
Their aggregate data is often sensitive, and most support access controls
appropriate to such content.</p>



<p>Let’s look back now to the intent of the New York State
Cybersecurity Requirements For Financial Services, with some thought to how a
framework and a GRC tool might specifically help:</p>



<p class="has-medium-font-size">KEY</p>



<figure class="wp-block-image is-resized"><img loading="lazy" decoding="async" src="https://www.doublechecksoftware.com/wp-content/uploads/2019/05/NIST-circle-1.jpg" alt="" class="wp-image-1377" width="248" height="239" srcset="https://www.doublechecksoftware.com/wp-content/uploads/2019/05/NIST-circle-1.jpg 414w, https://www.doublechecksoftware.com/wp-content/uploads/2019/05/NIST-circle-1-150x144.jpg 150w, https://www.doublechecksoftware.com/wp-content/uploads/2019/05/NIST-circle-1-300x288.jpg 300w" sizes="(max-width: 248px) 100vw, 248px" /></figure>



<figure class="wp-block-image"><img loading="lazy" decoding="async" width="667" height="1024" src="https://www.doublechecksoftware.com/wp-content/uploads/2019/05/Newer-SG-graphic-for-blog-4-v3-667x1024.jpg" alt="" class="wp-image-1396" srcset="https://www.doublechecksoftware.com/wp-content/uploads/2019/05/Newer-SG-graphic-for-blog-4-v3-667x1024.jpg 667w, https://www.doublechecksoftware.com/wp-content/uploads/2019/05/Newer-SG-graphic-for-blog-4-v3-98x150.jpg 98w, https://www.doublechecksoftware.com/wp-content/uploads/2019/05/Newer-SG-graphic-for-blog-4-v3-195x300.jpg 195w, https://www.doublechecksoftware.com/wp-content/uploads/2019/05/Newer-SG-graphic-for-blog-4-v3-768x1180.jpg 768w, https://www.doublechecksoftware.com/wp-content/uploads/2019/05/Newer-SG-graphic-for-blog-4-v3.jpg 921w" sizes="(max-width: 667px) 100vw, 667px" /></figure>



<p>There
is clearly a lot to be gained through the use of frameworks, and of GRC
tools.&nbsp; They add considerable structure
and a sense of process firmness to actions and efforts that may often seem
unrelated, duplicative, and of questionable business purpose on their own.&nbsp; They support discipline and enable staff to
function as professional process managers with regard to cyber, IT, and
operational risk, while contributing those benefits to audit, compliance,
regulatory review, and other areas benefiting from sound risk management
practices.</p>



<p>Compliance with regulations is, for many industries, a practical matter that’s part of business as usual. Frameworks of controls and practices, supported through careful, thoughtful implementation of quality GRC software tools, can bring these benefits of structured professional management to this challenging aspect of contemporary business. It certainly would be of great benefit to managing compliance with the New York State Cybersecurity Requirements For Financial Services Companies.</p>



<p></p>



<p>About the Author:</p>



<p>Simon Goldstein is an accomplished senior executive blending both technology and business expertise to formulate, impact, and achieve corporate strategies. A retired senior manager of Accenture’s IT Security and Risk Management practice, he has achieved results through the creation of customer value, business growth, and collaboration. An experienced change agent with primary experience in financial, technology, and retail industries, he’s led efforts to achieve ISO2700x certification and HIPAA compliance, as well as held credentials of CRISC, CISM, CISA.</p><p>The post <a href="https://www.doublechecksoftware.com/applying-nist-standards-to-managing-cyber-risk-and-regulatory-compliance/">Applying NIST Standards to Managing Cyber Risk and Regulatory Compliance</a> first appeared on <a href="https://www.doublechecksoftware.com">DoubleCheck Software</a>.</p>]]></content:encoded>
					
					<wfw:commentRss>https://www.doublechecksoftware.com/applying-nist-standards-to-managing-cyber-risk-and-regulatory-compliance/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">1359</post-id>	</item>
		<item>
		<title>Once Upon A Time in Cyber Land…From ATM’s to AI and Beyond</title>
		<link>https://www.doublechecksoftware.com/one-upon-a-time-in-cyber-landfrom-atms-to-ai-and-beyond/</link>
					<comments>https://www.doublechecksoftware.com/one-upon-a-time-in-cyber-landfrom-atms-to-ai-and-beyond/#respond</comments>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Mon, 04 Mar 2019 17:14:43 +0000</pubDate>
				<category><![CDATA[Audit Management]]></category>
		<category><![CDATA[Cyber Security Risk Management]]></category>
		<category><![CDATA[Enterprise Risk Management]]></category>
		<guid isPermaLink="false">https://www.doublechecksoftware.com/?p=1330</guid>

					<description><![CDATA[<p>I’m old enough to remember a time before ATM’s, cell phones, the internet, and portable computing in any number of form factors. No, there were no dinosaurs stealing my school lunch, and I didn’t learn to write on a clay tablet with a stick (despite what my now grown children might think). But the depth<a href="https://www.doublechecksoftware.com/one-upon-a-time-in-cyber-landfrom-atms-to-ai-and-beyond/">[...]</a></p>
<p>The post <a href="https://www.doublechecksoftware.com/one-upon-a-time-in-cyber-landfrom-atms-to-ai-and-beyond/">Once Upon A Time in Cyber Land…From ATM’s to AI and Beyond</a> first appeared on <a href="https://www.doublechecksoftware.com">DoubleCheck Software</a>.</p>]]></description>
										<content:encoded><![CDATA[<p>I’m old enough to remember a time before ATM’s, cell phones, the internet, and portable computing in any number of form factors. No, there were no dinosaurs stealing my school lunch, and I didn’t learn to write on a clay tablet with a stick (despite what my now grown children might think). But the depth of my field of vision extends back to some of the earliest arrivals of the computer and information technology advances that made their way into our everyday lives. Considering those technologies, and how they came to become ubiquitous to daily life today, offered some insights into the nature and challenges cyber security professionals must now address. We laid the behavioral groundwork to enable malicious actors, malware, and cyber-crime. We also helped foster a culture of trust that made cyber risks seem unlikely. And we continue to pay the price today. So, let’s step back today and look at where we were, how we got here, and what we can do about it tomorrow.</p>
<p>Once upon a time, people paid cash for their purchases. Credit cards were few, and the idea of “paying on time”, even through a credit card, was shunned whenever possible. So when people needed cash, they went to a bank, stood in line, and interacted with a bank teller. If they were not well known by their branch staff, they had to produce identification on the spot. Simple, safe, secure. Then ATM’s were introduced. They offered convenience, and were accessed using a plastic card indistinguishable from a credit card… familiarity, acceptance. Early ATM’s were often called cash machines (or automated teller machines) because they did little else but display balances and dispense cash. (Human Tellers did more). And using a card to gain access, coupled with bank marketing of the convenience and ease credit cards offered, began our love affair with both. The growing foundation of computerized account management, transaction processing, and funds transfer made possible by investment in mini and mainframe computers in central data centers, joined through dedicated communications networks, made everything seem effortless. And safe and trustworthy. There were humorous stories of people trying to “rob” ATM’s by hauling them away only to have the ATM yank their truck axles from under them… Credit card fraud was rarely reported. Everything was secured by 4 digit PIN’s, or maybe slightly longer ones used by a cautious few. “Good people” everywhere used both technologies.</p>
<p>Scaling computers down to tabletop or desktop size, complete with software to do useful things like record and manage financial and statistical data, automate document production, and prepare visual representations of ideas, plans, and results positioned them as work machines. Graphical user interfaces made them approachable by people outside of business, but they remained isolated tools for specific tasks. Dial-up services provided early access to remote resources, and exposed machines with no security provisions aside from a user ID and password to open an onboard account to anonymous access from afar. One week after my first purchase of a travel map from a dial-up service, my credit card was compromised, though the event was caught by my bank. Even then, in the 1980s banks had begun to monitor user credit card buying patterns and flagged suspicious out-of-pattern behavior. Banks had always evaluated risk as part of doing business. Customer computer use for retail events was just another risk. They had a jump, for the time being, on this emerging phenomenon. But people had no frame of reference, no history, and little or no available education about the possible cyber threats developing in parallel to the technology. Events were isolated, and often investigated, “handled”, and filed away, unreported outside the impacted organization. Education and awareness were limited to the small population of curious and aware computer scientists.</p>
<p>Computer viruses came into being in the 1980s too, first passed through shared disks, then, online boards and services, and finally, with the arrival of the internet, they achieved mass distribution. Steve Jobs may have thought he changed the world with the introduction of the first Macintosh, and its user-friendly graphical user interface, but Tim Berners-Lee and all those who contributed to the internet gave everyone a reason to have a computer, and to use one. With the internet, email, and electronic commerce, retail (in specific), brought convenience to the public once again. Chat followed email, first as an add-on, and later as a stand-alone application. Communication to anyone anywhere became quick, simple, and affordable. Shopping became easier than going to the mall, as working hours and family demands created lifestyles and needs outside traditional retail hours. It was like the invention of the telephone all over again, but now with pictures, products, video and so much more; and it was interactive!</p>
<p>But these feature and service advances rapidly outpaced consideration, attention, and effort to make them safe and secure. New software technologies, then called object-oriented programming, led to thoughts about new platform architectures where small dedicated programs called “apps” would define the overall utility of a computing device. Security was not at the forefront of the promotional seminars and workshops I attended on these advances. All too often I sat in meetings where security staff with awareness of cyber risks were silenced as the “product prevention” people, always asking that projects slow down to engineer security provisions into new designs and new product or service features from the start. But, in the rush to be first, to be better, to compete in a fast-paced marketplace of rapid innovation, developers and management everywhere adopted product development methods based upon multiple successive iterations to refine offerings, often leaving security to a “future release”. Scant start-up resources were prioritized to deliver competitive edge, and security was not in the public’s mind as a competitive feature. The “homes and businesses” were going online fast, with unlocked doors and open pathways to personal and financial information. It did not take long for malicious actors to begin to realize what was there for the taking, and begin its harvest in earnest.</p>
<p>Cyber criminals, first individuals or small groups of actors, later forming more organized and professionalized groups, were more technologically sophisticated than the user population they exploited. And, early on, services and firms did try to first warn and defer responsibility for security onto the user. Market resistance defeated that effort in relatively near term. As increasing awareness of viruses created demand, anti-virus and other security software products made way into the marketplace. Even novice end users began to be aware there were risks associated with online computing. Hardware vendors bundled anti-virus software with new computer purchases. Revenue streams were created to assure continual streams of updated anti-virus signature data to keep these products current and useful. Financial institutions, with much to lose, were often at the vanguard of security and cyber risk response, leveraging their past efforts to strengthen rules, user education, and protective technologies to detect, deflect, and recover from cyber intrusions. Multi-factor authentication and strong passwords became common features. News media began to investigate and report cyber breaches and crimes that threatened users’ ability to maintain and control their own personal identities. Horror stories of identity theft, financial loss, and the difficulties of recovery become commonplace. We had trusted too long, and paid too much for convenience.</p>
<p>Today the marketplace is much more aware of the risks associated with cyber activity. Security is a competitive advantage. Legislation governing breach reporting requirements is in place in every state, though no Federal law is currently on the books. Cyber security and risk management have become an important component of product and service development, at least more so than in the 1990s and early 2000s.</p>
<p>But we still repeat some of the mistakes of the past. Smart phones, other mobile devices, and social media’s rapid rise to ubiquity all too often have followed the path and errors of their larger desktop and laptop cousins. Security was not always a top priority, and today there are still concerns about shared data across apps and hacked access into smart phones though near field point-of-sale terminals, or social media platforms. Those issues are still being worked today. Device security is getting stronger. As mobile devices extend and blur the boundaries of corporate enterprises tools, processes and technologies are following closely to help manage and police device configurations, activity, authentication, and authenticity. App sources now scrutinize new product candidates for security provisions before publication.</p>
<p>Those processes are not perfect. The technologies underpinning social media platforms remain largely open and rich with aggregated user data subject to distribution and repurposing agreements that drive revenues under the radar of most users. Attorneys protect their client firms with vast, detailed end-user license agreements (EULA’s) that few read and fewer fully understand. But these platforms remain rich, inviting targets for malicious actors. User data, more than any other form, has truly become a form of currency with value at least the equal of any bitcoin.</p>
<p>The matter does not stop at social media and mobile platforms. Artificial intelligence creates an opportunity for gleaning more useful data from raw forms. Monitoring devices on streets, in stores and homes, in cars, and recently now at airplane seats are gathering more and more raw material to share with firms that will cultivate it into value and revenue streams. These technologies and practices open questions about individual privacy, ownership, and law. They also carry their own forms of cyber risk. Once again, now and in the foreseeable future, cyber risk and security professionals will need to continually evaluate, develop and refine processes, education, and technologies to identify, measure, and manage these risks as they enter modern life throughout developed and developing societies.</p>
<p>We have reached a point where the pages of technological advance, security, and cyber risk, must now turn as one. Cyber risk and security must take advantage of artificial intelligence, monitoring, and social platform management technologies too. Detection and identification of cyber threats will gain complexity as data gathering and repurposing gains diversity and complexity. Risk and security professionals must ensure the foundations of their programs form a solid basis for extended scope and sophistication in the future. Frameworks, tools, procedures, and processes will all be important attributes of any cyber risk program. Lawmakers, legislators, and ethicists also need to weigh in on how best to enable progress while preserving some reasonable level of personal privacy and safety.</p>
<p>It’s a long way from the stand-alone piece of automated machinery to our interconnected “smart” devices and practices. There is a dependence upon many connected services now, for finding our way in cars, keeping track of important dates, making purchases, staying in touch, and on and on… the list continues to grow, as does our dependence upon these technologies, ones to come, and the data cache it all creates. Now everyone, users, makers, security folk, lawmakers, and even apparent bystanders must become equally “smart” about security and managing the associated cyber risks of an ever-connected society.</p>
<p>About the Author:</p>
<p>Simon Goldstein is an accomplished senior executive blending both technology and business expertise to formulate, impact, and achieve corporate strategies. A retired senior manager of Accenture’s IT Security and Risk Management practice, he has achieved results through the creation of customer value, business growth, and collaboration. An experienced change agent with primary experience in financial, technology, and retail industries, he’s led efforts to achieve ISO2700x certification and HIPAA compliance, as well as held credentials of CRISC, CISM, CISA.</p><p>The post <a href="https://www.doublechecksoftware.com/one-upon-a-time-in-cyber-landfrom-atms-to-ai-and-beyond/">Once Upon A Time in Cyber Land…From ATM’s to AI and Beyond</a> first appeared on <a href="https://www.doublechecksoftware.com">DoubleCheck Software</a>.</p>]]></content:encoded>
					
					<wfw:commentRss>https://www.doublechecksoftware.com/one-upon-a-time-in-cyber-landfrom-atms-to-ai-and-beyond/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">1330</post-id>	</item>
		<item>
		<title>Addressing the Right Cyber Risk…. An Example</title>
		<link>https://www.doublechecksoftware.com/addressing-the-right-cyber-risk-an-example/</link>
					<comments>https://www.doublechecksoftware.com/addressing-the-right-cyber-risk-an-example/#comments</comments>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Wed, 13 Feb 2019 21:01:39 +0000</pubDate>
				<category><![CDATA[Audit Management]]></category>
		<category><![CDATA[Cyber Security Risk Management]]></category>
		<category><![CDATA[Enterprise Risk Management]]></category>
		<category><![CDATA[GRC Implementation Success]]></category>
		<guid isPermaLink="false">https://www.doublechecksoftware.com/?p=1294</guid>

					<description><![CDATA[<p>Recently there was a malware attack discovered. “So?”, you might ask?  “There’s always a malware attack of some sort or another being identified, reported and measured for its scope and impact.”  Well, this one was unique in several ways: First, it seemed to target Mac OS, which is a rarity for technical (its UNIX roots)<a href="https://www.doublechecksoftware.com/addressing-the-right-cyber-risk-an-example/">[...]</a></p>
<p>The post <a href="https://www.doublechecksoftware.com/addressing-the-right-cyber-risk-an-example/">Addressing the Right Cyber Risk…. An Example</a> first appeared on <a href="https://www.doublechecksoftware.com">DoubleCheck Software</a>.</p>]]></description>
										<content:encoded><![CDATA[<p>Recently there was a malware attack discovered. “<em>So?</em>”, you might ask?  “<em>There’s always a malware attack of some sort or another being identified, reported and measured for its scope and impact.</em>”  Well, this one was unique in several ways:</p>
<ul>
<li>First, it seemed to target Mac OS, which is a rarity for technical (its UNIX roots) and opportunity (tiny user population compared with Windows) reasons.</li>
<li>Second, the “malice” was limited to the ultimate introduction of adware.</li>
<li>Third, the code was concealed through the use of stenography (hiding code or other content within a picture or other object).</li>
</ul>
<p>At first glance, this seems to be a fairly sophisticated threat and one requiring a good amount of technical skill and resources to combat effectively.  Sometimes, appearances are more deceiving than code concealed by stenography. How the image’s embedded code was translated into action is not material to this article.  For those of you who are into those technical details, you can find them here: <a href="https://apple.news/A2VsoJrw3TaKChdEeE2j6_w"><strong>Malvertisers target Mac users with steganographic code stashed in images</strong> &#8211; <strong>Ars Technica</strong></a></p>
<p>What’s important to this discussion was that the code embedded in the image redirected Mac users to a website that served display ads.  These ads falsely claimed a visitor’s Flash Player was outdated and offered an update. Executing this “update” actually infected the user’s machine with something called Shlayer.  It’s a trojan, first noticed about 11 months ago, used to install adware.</p>
<p>While adware is a nuisance, it’s not an existential threat by itself.  Which is fortunate.  As a cyber risk professional, what’s the risk in this scenario?  Is it preventing adware from distracting users?  Gathering personal information and sharing it outside the company? A bit, perhaps.  And what remedies would you recommend be deployed? More monitoring of the periphery for and blocking inbound malware concealed with increasing sophistication?  Further strengthening platforms at users’ locations?  Restricting what platforms may be tied to company networks? Adding network monitoring technology and staff? All of these? Others?</p>
<p><strong><em>The real risk is in user behavior.</em> </strong>And uninformed, unaware users <strong><em>are</em></strong> an existential cyber risk! The approach of the malware attack just described fails completely if targeted users are mindful of where they go online; what and from where they download updates and other files; examining and vetting sources first before acting. It doesn’t matter that the redirecting code was concealed in an image and invisible to the user’s eye.  It doesn’t matter that stenography might defeat many malware monitoring technologies. And it doesn’t really matter that some users were working on Mac OS platforms.</p>
<p>What does matter is that users freely, and perhaps foolishly, trusted an unfamiliar site and chose to initiate a software update from an untrusted site.  THAT is how the malware/adware was installed!  The risk is that people may act in unsafe ways, from a cyber security perspective. They may ignore rules, policies, and published practices. Thoughtless action by users, both on staff and from supplier organizations, have been the root cause of several recent significant cyber attacks.  Not everyone has been “fortunate” enough to just receive adware in a download…much more malicious code could just as easily have been substituted, with devastating effect!</p>
<p>The beginning of each year is a great time to evaluate your cyber risk program from the perspective of user training and awareness. It’s a time when we are all looking out at the year ahead, formalizing plans, and preparing to execute them. This is the perfect context for considering cyber risk. What are the obstacles that would derail your organization’s plans, achievement of its goals, and progress for 2019? What cyber risks were most prevalent in your experience in the year just passed? What incidents occurred, and, more importantly, what was their root cause? How likely are they to recur and what would their impact be now?  How many might not have materialized had users been better informed and trained? Have new controls been implemented? If so, how aware are users of any controls that require a change to their behavior?  How are you planning to evaluate how well these have been understood and adopted across your user population?</p>
<p>A well-formed user awareness program is the first, and in many respects the strongest cyber risk control to implement across an enterprise.  Answering these 10 questions may help you address this “educational” risk:</p>
<ol>
<li>Do you have a plan for evaluating the effectiveness of your current user education program?</li>
<li>Are policies and procedures current?</li>
<li>Are users subject to at least annual refresher sessions on key practices?</li>
<li>Are pro-active processes in place to broadly communicate procedure and policy changes when they occur?</li>
<li>How do you measure user awareness and adoption?</li>
<li>What aspects of cyber security need more attention in your education program?</li>
<li>Are there plans to strengthen them?</li>
<li>Do you have evidence of your current position and where you need to be to support resource requests from Executive Management?</li>
<li>How do your most recent cyber risk assessments support your assertions and plans?</li>
<li>What leading metrics are monitored to identify a user awareness problem before it leads to a “front page” incident?</li>
</ol>
<p>An entire category within the core function PROTECT of the NIST Cybersecurity Framework v 1.1 deals specifically with user awareness and training;</p>
<p><img loading="lazy" decoding="async" class="alignnone wp-image-1308" src="https://www.doublechecksoftware.com/wp-content/uploads/2019/01/Protect-v5-300x64.jpg" alt="" width="778" height="166" srcset="https://www.doublechecksoftware.com/wp-content/uploads/2019/01/Protect-v5-300x64.jpg 300w, https://www.doublechecksoftware.com/wp-content/uploads/2019/01/Protect-v5-768x164.jpg 768w, https://www.doublechecksoftware.com/wp-content/uploads/2019/01/Protect-v5.jpg 978w" sizes="(max-width: 778px) 100vw, 778px" /></p>
<p>NIST also indicates where this imperative maps to other standards related to IT, risk, and security management.  Specifically:</p>
<ul>
<li>CIS CSC 17, 18</li>
<li>COBIT 5 APO07.03, BAI05.07</li>
<li>ISA 62443-2-1:2009 4.3.2.4.2</li>
<li>ISO/IEC 27001:2013 A.7.2.2, A.12.2.1</li>
<li>NIST SP 800-53 Rev. 4 AT-2, PM-13</li>
</ul>
<p>Depending upon the content, structure, and frequency of your risk assessment program you may have considerable data built into your current risk processes to evaluate your current situation. Combining these data with results of training efforts, communications programs, user testing (you do test how your users respond to possible phishing attacks and unvetted communications like those in this article, I hope) and incident tracking may offer a comprehensive understanding of strengths and opportunities for your user education program.</p>
<p>User education is a foundational practice.  It enables many other controls essential to cyber risk management, including access control (logical and physical), authentication, supplier management, and more.  Treating it as such will strengthen your overall risk program and help it yield results that will justify continued attention, support, and resource assignment from your Executive Management. And, it will help you assure active, effective, cyber risk management!</p>
<p><strong>Note:</strong> Another article, <a href="https://www.doublechecksoftware.com/test-post-for-another-category/"><strong>The Oft Transparent Link in Cyber Security’s Risk Chain — People!</strong></a> addresses many of the aspects of staff education critical to effective cyber security.</p>
<p>&nbsp;</p>
<p>About the Author:</p>
<p>Simon Goldstein is an accomplished senior executive blending both technology and business expertise to formulate, impact, and achieve corporate strategies. A retired senior manager of Accenture’s IT Security and Risk Management practice, he has achieved results through the creation of customer value, business growth, and collaboration. An experienced change agent with primary experience in financial, technology, and retail industries, he’s led efforts to achieve ISO2700x certification and HIPAA compliance, as well as held credentials of CRISC, CISM, CISA.</p><p>The post <a href="https://www.doublechecksoftware.com/addressing-the-right-cyber-risk-an-example/">Addressing the Right Cyber Risk…. An Example</a> first appeared on <a href="https://www.doublechecksoftware.com">DoubleCheck Software</a>.</p>]]></content:encoded>
					
					<wfw:commentRss>https://www.doublechecksoftware.com/addressing-the-right-cyber-risk-an-example/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">1294</post-id>	</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Page Caching using Disk: Enhanced 
Content Delivery Network via N/A
Lazy Loading (feed)
Minified using Disk
Database Caching 4/101 queries in 0.089 seconds using Disk (Request-wide modification query)

Served from: www.doublechecksoftware.com @ 2026-08-01 14:39:47 by W3 Total Cache
-->